CVE-2026-37530
7.5Automotive Grade Linux · agl-service-can-low-level
A stack buffer overflow in the Automotive Grade Linux agl-service-can-low-level service allows unauthenticated remote attackers to cause a denial of service.
Executive summary
A stack buffer overflow vulnerability in the Automotive Grade Linux agl-service-can-low-level service allows unauthenticated remote attackers to achieve a denial of service or potential remote code execution on target systems.
Vulnerability
This is a stack buffer overflow flaw located in the send_diagnostic_request function within the uds-c library. An unauthenticated attacker can send a crafted payload via network inputs to trigger the memory corruption.
Business impact
A successful exploit of this vulnerability can lead to system crashes or remote code execution, severely impacting the reliability and safety of automotive electronic control units. With a CVSS score of 7.5, the risk is classified as High due to the potential for network-based exploitation without requiring prior authentication or user interaction.
Remediation
Immediate Action: Apply the latest vendor security updates or patches provided by Automotive Grade Linux as soon as they become available.
Proactive Monitoring: Monitor network traffic for anomalous diagnostic requests directed at the CAN service and review system logs for unexpected reboots or crashes.
Compensating Controls: Implement network segmentation and strict firewall rules to restrict access to the affected automotive services to trusted internal networks only.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept reference exists on GitHub via the security researcher disclosure.
Analyst recommendation
Given the high severity of this vulnerability and the availability of a public proof-of-concept, administrators must prioritize mitigating network exposure and applying vendor updates immediately. Ensuring strict perimeter controls and monitoring for anomalous service behavior will help protect systems until official patches are fully deployed.