CVE-2026-82357

Source
https://cve.org/CVERecord?id=CVE-2026-82357
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82357.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82357
Published
2026-10-01T19:41:47Z
Modified
2026-10-03T08:03:11Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
RT-Labs AB C-Open CANopen NULL pointer dereference
Details

RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.

Database specific
{
    "cna_assigner":  "cisa-cg",
    "cwe_ids":  [
        "CWE-476"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82357.json"
}
References

Affected packages

Git / github.com/rtlabs-com/c-open

Affected ranges

Type
GIT
Repo
https://github.com/rtlabs-com/c-open
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.1.1"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

public/v1.*
public/v1.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82357.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "325124189572272260870311175552757248080",
            "length":  1636
        },
        "id":  "CVE-2026-82357-14019273",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "src/co_sdo_server.c",
            "function":  "co_sdo_rx_download_seg_req"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "272461627778368712007747684045902712041",
            "length":  245
        },
        "id":  "CVE-2026-82357-2040c33c",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "src/co_lss.c",
            "function":  "co_lss_identity_get"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "42002365070947738037223220353581527221",
            "length":  162
        },
        "id":  "CVE-2026-82357-320284ea",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "src/co_lss.c",
            "function":  "co_lss_init"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "164147392278730642748241061479189970780",
                "203878713004402079833562706097211232962",
                "36616733524128164312750524750112391345",
                "184011724265028255398845821010442293599"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-82357-5912d75d",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "samples/slave/slave.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "106088642351237489842622141963085583595",
                "294804620323865334729115160754181465791",
                "177164280203892796323396481439412612271",
                "248326608781997156811507574462112270840"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-82357-6293b1e4",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "test/test_util.h"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "314924377624210806205440908866671679246",
            "length":  607
        },
        "id":  "CVE-2026-82357-6b0c2a0b",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "src/co_lss.c",
            "function":  "co_lss_inquire_identity"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "266816321767689576519285662459928189713",
                "49362068846328814605457804122061796961",
                "287929551429695583010339431912881230300",
                "288850488669783553292776483383664877510",
                "63879643187827220328974635430171677939",
                "287929551429695583010339431912881230300"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-82357-8e27e279",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "src/co_sdo_server.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "243395724250237381427400046914416141459",
                "31433916477770798747325588839471215715",
                "257976297618390070030383337467454463079",
                "5242711043273888949991228422928685265",
                "90606467274305947059523405210967921996",
                "54844704610018267246297714523900539764",
                "147907157503994625138699193841728505049",
                "282477856285567365402150966133659714617",
                "332114166126657880949033532728448139205",
                "81815288020120805035736635117768597116",
                "219713907162302157231759612504008743719",
                "184891408626408031480477908573546665840",
                "48305270904910213964220257716210185667",
                "126525271293956646260090723958688731102",
                "336000195125429997682413119524712933449",
                "271240154073052200330035903826402909877",
                "176942762728670528751948003093638828292",
                "71375677890224760355768708580792307787",
                "81828347601982261933991283728757467542",
                "145285214347586748090034768455699017615",
                "280356284118779465758669038031113813348",
                "148515975041281695072210762710485509763",
                "174378154041941140982802537899033326660",
                "57823921473444506236460946385675493925",
                "197766511101439003124718431997910841005",
                "143770263343649922180970817138061590923",
                "311656363305188815492257137614791189754"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-82357-8f9dccb9",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "src/co_lss.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "243939391360276321077839900214661758168",
                "161633625510567069405448303105720623849",
                "34971806247636875429451207495255617917"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-82357-92f9b92f",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "test/test_sdo_server.cpp"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "331741183972024165610337617313325074997",
            "length":  1067
        },
        "id":  "CVE-2026-82357-bb8f60c9",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "src/co_sdo_server.c",
            "function":  "co_sdo_rx_upload_seg_req"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "190295048243472633345103552246730765234",
            "length":  910
        },
        "id":  "CVE-2026-82357-fc75be17",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/rtlabs-com/c-open/commit/8f367a56abb65b3fee81d9e250612d7138db87f9",
        "target":  {
            "file":  "samples/slave/slave.c",
            "function":  "slave_init"
        }
    }
]
vanir_signatures_modified
"2026-10-03T08:03:11Z"