CVE-2026-54413 Details
Description
driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-byte 0x27 SecurityAccess request that follows any earlier well-formed 0x27 message.
A vulnerability exists in the driftregion iso14229 library, specifically in versions through 0.9.0, within the Universal Diagnostic Services (UDS) implementation. The issue is an integer underflow combined with a downstream out-of-bounds read in the Handle_0x27_SecurityAccess function. This vulnerability allows a remote, unauthenticated attacker to crash a UDS server and potentially read memory beyond the receive buffer limit. The exploitation involves sending a single-byte 0x27 Security Access request that follows a well-formed 0x27 message. The vulnerable handler operates over CAN bus, OBD-II, ISO-TP, and DoIP transports, and is exposed in the default diagnostic session without prior authentication, affecting automotive ECUs, industrial controllers, and IoT devices that use iso14229 as their UDS server.
Users can update to version 0.9.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 14, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cwe.mitre.org/data/definitions/125.html | TuranSec | Not Applicable |
| https://cwe.mitre.org/data/definitions/191.html | TuranSec | |
| https://github.com/driftregion/iso14229 | TuranSec | Vendor |
| https://github.com/driftregion/iso14229/blob/main/iso14229.c#L1447 | TuranSec | Source CodeVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | TuranSec |
| CWE-191 | Integer Underflow (Wrap or Wraparound) | TuranSec |
Affected Products
| Product | Versions |
|---|---|
| driftregion iso14229 | <= 0.9.0 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 10, 2026 | CVE Modified | TuranSec |
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TuranSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 14, 2026 | New CVE Received | TuranSec |
Volerion