CVE-2023-26257: Covesa Dlt-Daemon

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c.

Affected products

  • Covesa Dlt-Daemon: up to and including 2.18.8

Published 2023-02-27. Last modified 2026-06-17.