8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.
AI Analysis
Out-of-bounds memory access in libais due to unchecked sentinel value in VdmStream::AddLine
Basic Information
ID
CVE-2026-56770
Source
VulnCheck
Published
Jun 25, 2026 at 18:06
Affected Product
Vendor
schwehr
Product
libais
Affected Versions
schwehr libais 0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
schwehr
Product
libais
Version
0.15