{"id":"CVE-2026-56790","summary":"CANBoat - Off-by-One Global Buffer Overflow in searchForPgn()","details":"CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. Attackers can deliver a crafted NMEA-2000 message with an out-of-range PGN value over CAN bus or N2K-over-IP to trigger an out-of-bounds array access and denial of service.","modified":"2026-08-12T16:09:54.568591Z","published":"2026-06-25T18:14:48.573Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56790.json","unresolved_ranges":[{"extracted_events":[{"last_affected":"6.22"}],"source":"AFFECTED_FIELD"},{"source":"DESCRIPTION","extracted_events":[{"fixed":"6.22"}]}],"cna_assigner":"VulnCheck","cwe_ids":["CWE-193"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56790.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56790"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/canboat-off-by-one-global-buffer-overflow-in-searchforpgn"},{"type":"REPORT","url":"https://github.com/canboat/canboat/pull/649"},{"type":"FIX","url":"https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f"},{"type":"PACKAGE","url":"https://github.com/canboat/canboat"},{"type":"EVIDENCE","url":"https://github.com/canboat/canboat/issues/644"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canboat/canboat","events":[{"introduced":"0"},{"fixed":"a5a22b74b9ac5688019cba62669df08562cebd6f"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v6.2.2","v6.2.1","v6.2.0","v6.1.9","v6.1.8","v6.1.7","v6.1.6","v6.1.5","v6.1.4","v6.1.3","v6.1.2","v6.1.1","v6.1.0","v6.0.1","v6.0.0","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.0.2","v5.0.1","v5.0.0","v4.12.0","v4.11.1","v4.11.0","v4.10.1","v4.10.0","v4.9.2","v4.9.1","v4.6.1","v4.6.0","v4.5.1","v4.5.0","v4.4.0","v4.3.0","v4.2.2","v4.2.1","v1.3.0","v1.2.1","v1.2.0","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56790.json","vanir_signatures_modified":"2026-08-12T16:09:54Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f","target":{"file":"analyzer/fieldtype.c","function":"getMaxRange"},"deprecated":false,"digest":{"function_hash":"168646361418733158296917339245976847655","length":716},"id":"CVE-2026-56790-4e64e5e0"},{"digest":{"length":526,"function_hash":"222464156335230568715815585472264728586"},"id":"CVE-2026-56790-67749b77","signature_type":"Function","signature_version":"v1","source":"https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f","target":{"file":"analyzer/pgn.c","function":"searchForPgn"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["84804944001708472537401909121786812030","7637280945120140124334134607518106748","245979448189228892888550498670119739206","238056407912069975948210360828863689424","68938824326976598631450060431016958888","263989437318060016459419116078366417946","84430242384305060900685103642622740984","24777401864815532248060354936870385941","38915506900629647424817909979924168794","315987240199776194661868774126886613113","104826243171936960986668911379521780813","89808255146223516690064754196603008458","25810975646970340466747645912118872004","85834876339305817964261666691332803308","139945435346901804202572933081269576134","272087703181985716020628159662661709470","319976298555995032642663567821675244287","209330561589510182748005471655590004350","110892944002911242813675019736756640399","41110381038975873116901829162051431332","97499783404307896181566490242486018189","136065763809526117010996913358501953116"],"threshold":0.9},"id":"CVE-2026-56790-78667822","signature_type":"Line","signature_version":"v1","source":"https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f","target":{"file":"analyzer/pgn.c"}},{"target":{"file":"analyzer/fieldtype.c"},"deprecated":false,"digest":{"line_hashes":["163098978244034999688155661080979170026","92690140463484657956663568309384359244","31122712908405352380486592617022802753","255019475668244505269973778839645276821"],"threshold":0.9},"id":"CVE-2026-56790-b732f649","signature_type":"Line","signature_version":"v1","source":"https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"}]}