Infinite loop in scapy - #VU146808
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to loop with unreachable exit condition in the ISOTPSoftSocket receive scheduler when handling a rejected ISO-TP consecutive frame. A remote user can send a specially crafted CAN frame sequence to cause a denial of service.
User interaction is required to open and use an affected ISOTPSoftSocket, and the condition can persist after the crafted frames are consumed without continued traffic.