


Perceptive Security
SOC/SIEM Consultancy

miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diagnostic_request. A 6-byte stack buffer (M…
Published:
30 april 2026 om 22:00:00
Alert date:
1 mei 2026 om 18:06:04
Source:
nvd.nist.gov
Mobile & IoT
CVE-2026-37536 affects the miaofng/uds-c library in a commit from 2016-10-05. The vulnerability is a stack buffer overflow in the send_diagnostic_request function. A 6-byte stack buffer receives memcpy operations that can write up to 10 bytes, exceeding the buffer by 4 bytes. The issue occurs because there is no bounds checking on payload_length before the memcpy operation. This could potentially allow attackers to execute arbitrary code or crash the application.
Technical details
Mitigation steps:
Affected products:
miaofng/uds-c
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-37536
https://gist.github.com/sgInnora/f4ac66faeefe07a653ceeb3f58cdc381
https://github.com/miaofng/uds-c
https://github.com/openxc/uds-c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
