SB2026090294 - Infinite loop in scapy
Published: September 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Infinite loop (CVE-ID: N/A)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to loop with unreachable exit condition in the ISOTPSoftSocket receive scheduler when handling a rejected ISO-TP consecutive frame. A remote user can send a specially crafted CAN frame sequence to cause a denial of service.
User interaction is required to open and use an affected ISOTPSoftSocket, and the condition can persist after the crafted frames are consumed without continued traffic.
Remediation
Install update from vendor's website.