CVE-2026-54413
iso14229 Integer Underflow and Out-of-Bounds Read in Handle_0x27_SecurityAccess()
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-byte 0x27 SecurityAccess request that follows any earlier well-formed 0x27 message.
| CWE | CWE-191 CWE-125 |
| Vendor | driftregion |
| Product | iso14229 |
| Published | Jun 14, 2026 |
| Last Updated | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for driftregion iso14229
Be the first to know when new high vulnerabilities affecting driftregion iso14229 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
High
Affected Versions
driftregion / iso14229
0 โค 0.9.0
References
Credits
Burxonov Muslimbek