CVE-2026-56790 Details
Description
CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. Attackers can deliver a crafted NMEA-2000 message with an out-of-range PGN value over CAN bus or N2K-over-IP to trigger an out-of-bounds array access and denial of service.
A global buffer overflow vulnerability has been identified in CANBoat versions through 6.22, within the 'searchForPgn()' function of 'analyzer/pgn.c'. This vulnerability allows remote attackers to cause a denial-of-service by sending a crafted NMEA-2000 message with an out-of-range PGN value, either over CAN bus or N2K-over-IP. The flaw arises from improper handling of PGN values, leading to out-of-bounds array access and application crashes.
Users can update to CANBoat version 6.23 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f | [email protected] | Source CodeVendor |
| https://github.com/canboat/canboat/issues/644 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
| https://github.com/canboat/canboat/pull/649 | [email protected] | Source CodeVendor |
| https://www.vulncheck.com/advisories/canboat-off-by-one-global-buffer-overflow-in-searchforpgn | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-193 | Off-by-one Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CANBoat | <= 6.22 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion