Out-of-Bounds Stack Read in nanoMODBUS Affects Modbus Protocol Functionality
CVE-2026-71256
9.8CRITICAL
What is CVE-2026-71256?
The vulnerability in nanoMODBUS arises from an out-of-bounds stack read due to inadequate boundary checking when handling object IDs. Specifically, in the function nmbs_read_device_identification_basic(), server-supplied object IDs that exceed predefined limits can lead to the reading of garbage stack data and potential arbitrary memory writes. This poses significant risks, including the possibility for attackers to manipulate memory by exploiting the wild pointers generated during processing of responses from malicious Modbus servers.
Affected Version(s)
nanoMODBUS 0 <= 1.23.0
