Covesa maintains the DLT Daemon, a diagnostic logging and tracing system for embedded automotive platforms, with a compact but strategically significant footprint in vehicle diagnostics and software analysis infrastructure. The observed vulnerability pattern centers on memory-management issues characteristic of native logging code: classic buffer overflows from unchecked input sizes and failure to release memory after its effective lifetime. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Covesa over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26257HIGH An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-c | Feb 27, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-36321HIGH Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.c. | Oct 17, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Covesa.
Media articles that mention a CVE ID that affects a product developed by Covesa — matched by CVE ID, not by vendor name.