---
id: CVE-2026-14605
title: A vulnerability was identified in RT-Thread up to 5.0.2
summary: >-
  A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this
  vulnerability is the function recvmsg in the library
  bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler.
  Such manipulation leads to stack-…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-121
published: '2026-07-03'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14605'
references:
  - url: 'https://github.com/RT-Thread/rt-thread/'
    label: cna@vuldb.com
  - url: 'https://github.com/RT-Thread/rt-thread/issues/11424'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-14605'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/844580'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/376113'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/376113/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-04T10:56:04.376Z'
epss: 0.00197
epssPercentile: 0.08438
---

## Overview

A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
