Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 04 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Miaofng
Miaofng uds-c |
|
| Vendors & Products |
Miaofng
Miaofng uds-c |
Sat, 02 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stack Buffer Overflow in uds-c send_diagnostic_request Function |
Fri, 01 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 | |
| Metrics |
ssvc
|
Fri, 01 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diagnostic_request. A 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD_SIZE=6) receives memcpy at offset 1+pid_length with payload_length bytes. MAX_UDS_REQUEST_PAYLOAD_LENGTH=7, so 1+2+7=10 exceeds buffer by 4 bytes. No bounds check on payload_length before memcpy. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-01T19:45:05.053Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37536
Updated: 2026-05-01T19:32:29.811Z
Status : Awaiting Analysis
Published: 2026-05-01T17:16:23.373
Modified: 2026-05-07T15:53:49.717
Link: CVE-2026-37536
No data.
OpenCVE Enrichment
Updated: 2026-05-04T19:44:42Z