CVE-2026-26264 – BACnet Stack WriteProperty decoding length underflow leads to OOB read and crash

CVE ID : CVE-2026-26264

Published : Feb. 13, 2026, 7:17 p.m. | 1 hour, 12 minutes ago

Description : BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.5.0rc4 and 1.4.3rc2, a malformed WriteProperty request can trigger a length underflow in the BACnet stack, leading to an out‑of‑bounds read and a crash (DoS). The issue is in wp.c within wp_decode_service_request. When decoding the optional priority context tag, the code passes apdu_len – apdu_size to bacnet_unsigned_context_decode without validating that apdu_size
Severity: 7.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… 

نوشته های مشابه