CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. Attackers can deliver a crafted NMEA-2000 message with an out-of-range PGN value over CAN bus or N2K-over-IP to trigger an out-of-bounds array access and denial of service.
{
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"last_affected": "6.22"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "6.22"
}
]
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56790.json",
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-193"
]
}"2026-08-12T16:09:54Z"
[
{
"digest": {
"function_hash": "168646361418733158296917339245976847655",
"length": 716.0
},
"signature_type": "Function",
"source": "https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f",
"id": "CVE-2026-56790-4e64e5e0",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "analyzer/fieldtype.c",
"function": "getMaxRange"
}
},
{
"digest": {
"function_hash": "222464156335230568715815585472264728586",
"length": 526.0
},
"signature_type": "Function",
"source": "https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f",
"id": "CVE-2026-56790-67749b77",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "analyzer/pgn.c",
"function": "searchForPgn"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"84804944001708472537401909121786812030",
"7637280945120140124334134607518106748",
"245979448189228892888550498670119739206",
"238056407912069975948210360828863689424",
"68938824326976598631450060431016958888",
"263989437318060016459419116078366417946",
"84430242384305060900685103642622740984",
"24777401864815532248060354936870385941",
"38915506900629647424817909979924168794",
"315987240199776194661868774126886613113",
"104826243171936960986668911379521780813",
"89808255146223516690064754196603008458",
"25810975646970340466747645912118872004",
"85834876339305817964261666691332803308",
"139945435346901804202572933081269576134",
"272087703181985716020628159662661709470",
"319976298555995032642663567821675244287",
"209330561589510182748005471655590004350",
"110892944002911242813675019736756640399",
"41110381038975873116901829162051431332",
"97499783404307896181566490242486018189",
"136065763809526117010996913358501953116"
]
},
"signature_type": "Line",
"source": "https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f",
"id": "CVE-2026-56790-78667822",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "analyzer/pgn.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"163098978244034999688155661080979170026",
"92690140463484657956663568309384359244",
"31122712908405352380486592617022802753",
"255019475668244505269973778839645276821"
]
},
"signature_type": "Line",
"source": "https://github.com/canboat/canboat/commit/a5a22b74b9ac5688019cba62669df08562cebd6f",
"id": "CVE-2026-56790-b732f649",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "analyzer/fieldtype.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56790.json"