CVE-2026-42467
7.5Open-SAE-J1939 Project · Open-SAE-J1939
A denial of service vulnerability in Open-SAE-J1939 allows attackers to crash systems via crafted CAN frames on the J1939 bus.
Executive summary
An unauthenticated denial of service vulnerability in Open-SAE-J1939 allows attackers to disrupt critical bus communications via crafted CAN frames.
Vulnerability
This is a denial of service vulnerability residing in the SAE_J1939_Read_Binary_Data_Transfer_DM16 function, triggered by an unauthenticated attacker using crafted CAN frames on the J1939 bus.
Business impact
A successful exploit results in the disruption of critical vehicular or industrial bus communications, leading to potential system downtime and operational failure. With a CVSS score of 7.5, this high severity flaw poses significant risks to environments relying on real-time telemetry and control data.
Remediation
Immediate Action: Apply upstream patches or updates as soon as the vendor provides a formal fix for the affected commit range.
Proactive Monitoring: Monitor network and bus traffic for anomalous or malformed CAN frames that could indicate probing or attack attempts.
Compensating Controls: Implement physical or network segmentation on the CAN bus to restrict unauthorized access to the J1939 interface.
Exploitation status
Public Exploit Available: No (referencing the GitHub Gist write-up, no weaponized exploit or public exploit module currently exists).
Analyst recommendation
Given the high severity score and the potential for complete service disruption on the J1939 bus, organizations should treat this issue with elevated priority. Security teams must monitor the repository for official remediation commits and apply updates immediately upon release.