« Volver al listado

CVE-2026-5071

Estado: AnalizadaAlta (7.8)—

The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in socketcan_to_can_frame(). In production builds where assertions are disabled, a userspace application that controls the length passed to a sendto syscall can supply an incomplete or truncated frame, causing socketcan_to_can_frame() to dereference fields beyond the end of the buffer. This results in an out-of-bounds read that can cause denial-of-service crashes or, because the parsed frame contents are transmitted on the network, leak adjacent memory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local (AV:L, PR:L) sin interacción del usuario permite escalada explotando validación deshabilitada en producción; causa DoS (crash) y fuga de memoria adyacente.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-5071",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-5071",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-01T13:51:23.839460Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vulnerabilities@zephyrproject.org",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerabilities@zephyrproject.org",
      "affectedData": [
        {
          "repo": "https://github.com/zephyrproject-rtos/zephyr",
          "vendor": "zephyrproject-rtos",
          "product": "Zephyr",
          "versions": [
            {
              "status": "affected",
              "version": "*",
              "versionType": "git",
              "lessThanOrEqual": "4.3"
            }
          ],
          "packageName": "Zephyr",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-30T08:16:16.370",
  "references": [
    {
      "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c3w6-x7m3-3c58",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "vulnerabilities@zephyrproject.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vulnerabilities@zephyrproject.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-125"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in socketcan_to_can_frame(). In production builds where assertions are disabled, a userspace application that controls the length passed to a sendto syscall can supply an incomplete or truncated frame, causing socketcan_to_can_frame() to dereference fields beyond the end of the buffer. This results in an out-of-bounds read that can cause denial-of-service crashes or, because the parsed frame contents are transmitted on the network, leak adjacent memory."
    },
    {
      "lang": "es",
      "value": "La implementación de SocketCAN valida la longitud de un búfer proporcionado por el usuario que contiene un objeto socketcan_frame utilizando únicamente una declaración NET_ASSERT en zcan_sendto_ctx() antes de desreferenciarlo en socketcan_to_can_frame(). En compilaciones de producción donde las aserciones están deshabilitadas, una aplicación en espacio de usuario que controla la longitud pasada a una llamada al sistema sendto puede proporcionar una trama incompleta o truncada, haciendo que socketcan_to_can_frame() desreferencie campos más allá del final del búfer. Esto resulta en una lectura fuera de límites que puede causar fallos por denegación de servicio o, debido a que el contenido de la trama analizada se transmite por la red, filtrar memoria adyacente."
    }
  ],
  "lastModified": "2026-07-22T06:10:00.170",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:zephyrproject:zephyr:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D912614-A39E-4C9B-AA54-187BC26337B9",
              "versionEndIncluding": "4.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vulnerabilities@zephyrproject.org"
}