SB2026090294 - Infinite loop in scapy



SB2026090294 - Infinite loop in scapy

Published: September 2, 2026

Security Bulletin ID SB2026090294
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Infinite loop (CVE-ID: N/A)

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

CVSSv4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to loop with unreachable exit condition in the ISOTPSoftSocket receive scheduler when handling a rejected ISO-TP consecutive frame. A remote user can send a specially crafted CAN frame sequence to cause a denial of service.

User interaction is required to open and use an affected ISOTPSoftSocket, and the condition can persist after the crafted frames are consumed without continued traffic.


Remediation

Install update from vendor's website.