{"id":"CVE-2026-71256","summary":"nanoMODBUS Client-Side Out-of-Bounds Read Leading to Wild-Pointer Write via object_id","details":"nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic() / recv_read_device_identification_res() in nanomodbus.c. A fixed 3-element stack array order[3] = {0,1,2} maps object IDs to buffer indices. The server-supplied object_id field (0-255, read directly from the wire) is used without any bounds check as buf_index = order[object_id]. When a malicious Modbus server sends a Read Device Identification response with object_id \u003e= 3, this reads an out-of-bounds/garbage byte from the stack adjacent to order[], which is then used as an index into a 3-element buffers[] array of char* pointers. The resulting wild pointer is passed to strncpy() as the destination, causing an arbitrary-address write with server-controlled data.","modified":"2026-08-07T22:16:20.996505Z","published":"2026-08-05T11:44:21.992Z","database_specific":{"cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71256.json","cna_assigner":"TuranSec"},"references":[{"type":"WEB","url":"https://github.com/debevv/nanoMODBUS/blob/master/nanomodbus.c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71256.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71256"},{"type":"PACKAGE","url":"https://github.com/debevv/nanoMODBUS"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/debevv/nanomodbus","events":[{"introduced":"0"},{"fixed":"91d6782930ee263bc760f27b0cbc5b82773c5f0d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.23.0"},{"fixed":"v1.23.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v1.22.1","v1.22.0","v1.21.0","v1.20.1","v1.20.0","v1.19.0","v1.18.1","v1.17.3","v1.17.2","v1.17.1","v1.17.0","v1.16.0","v1.15.0","v1.14.3","v1.14.2","v1.14.1","v1.14.0","v1.13.0","v1.12.1","v1.12.0","v1.11.0","v1.10.0","v1.9.1","v1.9.0","v1.8.1","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.1","v1.3.0","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.1","v1.0.0","v1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71256.json","vanir_signatures_modified":"2026-08-07T22:16:20Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"43930683384586369989119764856046191633","length":706},"id":"CVE-2026-71256-2e2d87d4","signature_type":"Function","signature_version":"v1","source":"https://github.com/debevv/nanomodbus/commit/91d6782930ee263bc760f27b0cbc5b82773c5f0d","target":{"function":"recv_read_registers_res","file":"nanomodbus.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/debevv/nanomodbus/commit/91d6782930ee263bc760f27b0cbc5b82773c5f0d","target":{"function":"handle_read_discrete","file":"nanomodbus.c"},"deprecated":false,"digest":{"function_hash":"191132749338481715068679544708146536524","length":1432},"id":"CVE-2026-71256-4c0320ff"},{"id":"CVE-2026-71256-b809b9fb","signature_type":"Function","signature_version":"v1","source":"https://github.com/debevv/nanomodbus/commit/91d6782930ee263bc760f27b0cbc5b82773c5f0d","target":{"file":"nanomodbus.c","function":"handle_write_multiple_coils"},"deprecated":false,"digest":{"function_hash":"138244319710543192589913111859839260296","length":1771}},{"deprecated":false,"digest":{"line_hashes":["6757658592252049191057077353244594635","173246798663779492191044794472711644388","201123161981660887808582356630476593494","182970786455787802761837060624754277229","324060117404835209103030211721901139917","335629579770334951107761008378484268341","193846363705036862041434221672979808921","228317482186195778445627755958617538317","319494073574386167987923512798064539398","237211782954421548721720002283344651838","40565148437630482060728325690066681375","245103394802154470089796992133834878339","228996339500900752227192895831538573313","23872434491142496420915001156559729678","328346009684504319704411398779077611592","192041551300145493868691064806977755858","301049820610973897629895682089142193585","45473464109489739649048246195543217222","257102493345768540969940681802047049855","33390113032853571136115251443084049106","286970104490934229061815146048932275335","119672187298319876631512538197931989352","226293647693874060624860032522331467745","81065135462443072107319482318908882641","49140238898704186397665095831526913425","335981277227297077837754786656756923171","89088247926131137423214924161945828538","289985426966966636035335922428145383457","74590402505412851979088559463323930823","143178722018170079987364021331770611440","249472076923746384794548633458630698387","95260750019989558129126938874883634248","288861144493816911499420574997496246718","230197994169092124818684262100174972677","250568708632035917884741266292448655984","99196889745262399818210635171913294344","319438313745715048738128980743057278659","63946976407189256434153205335558616656","166511411236362991243866167831925324681","250005773725542749478623920674101815461","24637633890142857819744908034669317081","48472177227951349649668850429642346960","165193918795874516602931879375331241207","333784346461106547210947923506018608774","26195871720017948723930733293126203077","24575271609143215469139061057734279794","185668929970272466715969832823365445776","163560789742937855828650234305907981125","168201067578329771742770587165716151840","93085375775645235313458456919395331966","254819460901069791143612979712653562541"],"threshold":0.9},"id":"CVE-2026-71256-c3fa9421","signature_type":"Line","signature_version":"v1","source":"https://github.com/debevv/nanomodbus/commit/91d6782930ee263bc760f27b0cbc5b82773c5f0d","target":{"file":"nanomodbus.c"}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}