UNKNOWNCVE-2026-23995

EVerest has stack buffer overflow in ifreq.ifr_name when interface name exceeds IFNAMSIZ

Platform

linux

Component

everest

Fixed in

2026.02.0

EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (16) to CAN open routines overflows `ifreq.ifr_name`, corrupting adjacent stack data and enabling potential code execution. A malicious or misconfigured interface name can trigger this before any privilege checks. Version 2026.02.0 contains a patch.

How to fix

Actualice EVerest a la versión 2026.02.0 o posterior. Esta versión contiene una corrección para el desbordamiento de búfer basado en pila en la inicialización de la interfaz CAN.

Monitor your dependencies automatically

Get notified when new vulnerabilities affect your projects. Free forever.

Start free