CVE-2026-14606

Source
https://cve.org/CVERecord?id=CVE-2026-14606
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14606.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-14606
Published
2026-07-03T19:30:08.022Z
Modified
2026-07-15T01:49:10.911720572Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
RT-Thread SWM341 CAN SWM341.h CAN_Receive stack-based overflow
Details

A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CANReceive in the library bsp/synwit/libraries/SWM341CSL/CMSIS/DeviceSupport/SWM341.h of the component SWM341 CAN Handler. Performing a manipulation results in stack-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14606.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-121"
    ]
}
References

Affected packages

Git / github.com/rt-thread/rt-thread

Affected ranges

Type
GIT
Repo
https://github.com/rt-thread/rt-thread
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "last_affected": "5.0.0"
        },
        {
            "introduced": "5.0.1"
        },
        {
            "last_affected": "5.0.1"
        },
        {
            "introduced": "5.0.2"
        },
        {
            "last_affected": "5.0.2"
        }
    ]
}

Affected versions

5.*
5.0.0
5.0.1
5.0.2
v5.*
v5.0.0
v5.0.1
v5.0.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14606.json"