---
id: CVE-2026-82357
title: >-
  RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS
  protocol is used to configure the device
summary: >-
  RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS
  protocol is used to configure the device. An object defined by the user
  application may not have all required subindexes for object 0x1018. An
  unauthenticated, remo…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: RT-Labs AB
product: C-Open
affected:
  - C-Open < 1.1.1
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T20:34:45.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82357'
references:
  - url: 'https://github.com/rtlabs-com/c-open/releases/tag/public%2Fv1.1.1'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-275-02.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://rt-labs.com/wp-content/uploads/2026/09/RRTL-260929-01.pdf'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-82357'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T19:58:57.564Z'
---

## Overview

RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
