{"id":"CVE-2026-71255","summary":"nanoMODBUS Client-Side Out-of-Bounds Write via object_length in recv_read_device_identification_res()","details":"nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res() function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never validated against the caller-supplied buffers_length parameter. After copying data with strncpy(buffers_out[buf_index], str, buffers_length), the code unconditionally writes a NUL terminator at buffers_out[buf_index][object_length]. When a malicious or compromised Modbus server sends a response with object_length greater than or equal to the client's buffers_length, this NUL write lands past the end of the caller-provided buffer, corrupting adjacent stack or heap memory on the client.","modified":"2026-08-07T21:55:20.137091Z","published":"2026-08-05T11:44:21.097Z","database_specific":{"cna_assigner":"TuranSec","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71255.json"},"references":[{"type":"WEB","url":"https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71255.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71255"},{"type":"PACKAGE","url":"https://github.com/debevv/nanoMODBUS"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/debevv/nanomodbus","events":[{"introduced":"0"},{"fixed":"91d6782930ee263bc760f27b0cbc5b82773c5f0d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.23.0"},{"fixed":"v1.23.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v1.22.1","v1.22.0","v1.21.0","v1.20.1","v1.20.0","v1.19.0","v1.18.1","v1.17.3","v1.17.2","v1.17.1","v1.17.0","v1.16.0","v1.15.0","v1.14.3","v1.14.2","v1.14.1","v1.14.0","v1.13.0","v1.12.1","v1.12.0","v1.11.0","v1.10.0","v1.9.1","v1.9.0","v1.8.1","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.1","v1.3.0","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.1","v1.0.0","v1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71255.json","vanir_signatures_modified":"2026-08-07T21:55:20Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"43930683384586369989119764856046191633","length":706},"id":"CVE-2026-71255-2e2d87d4","signature_type":"Function","signature_version":"v1","source":"https://github.com/debevv/nanomodbus/commit/91d6782930ee263bc760f27b0cbc5b82773c5f0d","target":{"file":"nanomodbus.c","function":"recv_read_registers_res"}},{"source":"https://github.com/debevv/nanomodbus/commit/91d6782930ee263bc760f27b0cbc5b82773c5f0d","target":{"file":"nanomodbus.c","function":"handle_read_discrete"},"deprecated":false,"digest":{"function_hash":"191132749338481715068679544708146536524","length":1432},"id":"CVE-2026-71255-4c0320ff","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/debevv/nanomodbus/commit/91d6782930ee263bc760f27b0cbc5b82773c5f0d","target":{"file":"nanomodbus.c","function":"handle_write_multiple_coils"},"deprecated":false,"digest":{"function_hash":"138244319710543192589913111859839260296","length":1771},"id":"CVE-2026-71255-b809b9fb","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["6757658592252049191057077353244594635","173246798663779492191044794472711644388","201123161981660887808582356630476593494","182970786455787802761837060624754277229","324060117404835209103030211721901139917","335629579770334951107761008378484268341","193846363705036862041434221672979808921","228317482186195778445627755958617538317","319494073574386167987923512798064539398","237211782954421548721720002283344651838","40565148437630482060728325690066681375","245103394802154470089796992133834878339","228996339500900752227192895831538573313","23872434491142496420915001156559729678","328346009684504319704411398779077611592","192041551300145493868691064806977755858","301049820610973897629895682089142193585","45473464109489739649048246195543217222","257102493345768540969940681802047049855","33390113032853571136115251443084049106","286970104490934229061815146048932275335","119672187298319876631512538197931989352","226293647693874060624860032522331467745","81065135462443072107319482318908882641","49140238898704186397665095831526913425","335981277227297077837754786656756923171","89088247926131137423214924161945828538","289985426966966636035335922428145383457","74590402505412851979088559463323930823","143178722018170079987364021331770611440","249472076923746384794548633458630698387","95260750019989558129126938874883634248","288861144493816911499420574997496246718","230197994169092124818684262100174972677","250568708632035917884741266292448655984","99196889745262399818210635171913294344","319438313745715048738128980743057278659","63946976407189256434153205335558616656","166511411236362991243866167831925324681","250005773725542749478623920674101815461","24637633890142857819744908034669317081","48472177227951349649668850429642346960","165193918795874516602931879375331241207","333784346461106547210947923506018608774","26195871720017948723930733293126203077","24575271609143215469139061057734279794","185668929970272466715969832823365445776","163560789742937855828650234305907981125","168201067578329771742770587165716151840","93085375775645235313458456919395331966","254819460901069791143612979712653562541"],"threshold":0.9},"id":"CVE-2026-71255-c3fa9421","signature_type":"Line","signature_version":"v1","source":"https://github.com/debevv/nanomodbus/commit/91d6782930ee263bc760f27b0cbc5b82773c5f0d","target":{"file":"nanomodbus.c"}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}