CVE-2026-23995General(linuxfoundation / everest)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (16) to CAN open routines overflows `ifreq.ifr_name`, corrupting adjacent stack data and enabling potential code execution. A malicious or misconfigured interface name can trigger this before any privilege checks. Version 2026.02.0 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • everest

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-26); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
everest

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-29: 103-2603-29
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-261
General1
2026-03-291
Disclosure1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-23995 EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer th… https://www.cve.org/CVERecord?id=CVE-2026-23995

    Post summary

    The excerpt announces a newly disclosed stack‑based buffer overflow in EVerest’s CAN interface before version 2026.02.0, providing basic technical details but no PoC, exploit code, or patch information.

    0001088
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-23995 - High EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initialization: passing an interface name longer than IFNAMSIZ (16) to CAN o... https://www.thehackerwire.com/vulnerability/CVE-2026-23995/ https://t.co/ueoYX8a8xq

    Post summary

    The post discloses a high‑severity stack‑based buffer overflow in EVerest’s CAN interface initialization before v2026.02.0, providing technical details but lacking PoC, exploit, patch, or active exploitation information.

    0000038
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxfoundationeverest---

Explore more