Infinite loop in scapy - #VU146808

 

Infinite loop in scapy - #VU146808

Published: September 2, 2026


Vulnerability identifier: #VU146808
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-835
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to loop with unreachable exit condition in the ISOTPSoftSocket receive scheduler when handling a rejected ISO-TP consecutive frame. A remote user can send a specially crafted CAN frame sequence to cause a denial of service.

User interaction is required to open and use an affected ISOTPSoftSocket, and the condition can persist after the crafted frames are consumed without continued traffic.


Affected software

scapy

Remediation

Install security update from vendor's website.

scapy - update to 2.8.0

External References

Related Security Bulletins