Impact
A buffer overflow in the recvmsg function of the ls1c CAN handler allows an attacker to corrupt the stack when a CAN message is processed. The flaw, indexed as CWE-119 and CWE-121, can lead to arbitrary code execution, denial of service, or other integrity and availability compromises. The vulnerability is limited to local execution; it cannot be triggered from remote hosts without local CAN access.
Affected Systems
RT‑Thread firmware versions up to and including 5.0.2 that include the ls1c CAN implementation in bsp/loongson/ls1cdev/libraries/ls1c_can.h are affected. Devices that expose the LS1C CAN interface to local traffic—such as embedded automotive or industrial controllers—are at risk if they run any of these vulnerable builds.
Risk and Exploitability
Given a CVSS score of 8.5 the issue is high severity. The EPSS score is below 1 % and the vulnerability is not yet in the CISA KEV catalog, yet a public exploit exists. Based on the description it is inferred that an attacker must have local access to the CAN controller to deliver a malicious message, but once local access is achieved the exploitation probability is realistic. For deployments where local CAN access is unrestricted, the risk of successful compromise remains significant.
OpenCVE Enrichment