Genivi maintains the Diagnostic Log and Trace software framework, a specialized diagnostic and telemetry component that, despite a narrow product scope, serves a critical role in automotive and embedded systems where visibility into system behavior is essential. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity and recurrence across memory-safety and input-handling weakness classes including out-of-bounds writes, double frees, NULL-pointer dereferences, and improper input validation that are typical of C-language diagnostic middleware. Defenders deploying this framework should treat security updates as priority patches given the severity profile and its privileged position in system logging and event collection; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Genivi over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36244CRITICAL The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon | Feb 10, 2021 | 9.8 | 33 | NO | NO |
CVE-2020-29394HIGH A buffer overflow in the dlt_filter_load function in dlt_common.c from dlt-daemon through 2.18.5 (GENIVI Diagnostic Log and Trace) allows arbitrary code execution because fscanf is | Nov 30, 2020 | 7.8 | 26 | NO | NO |
CVE-2022-31291HIGH An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets. | Jun 16, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-29507MEDIUM GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2.18.6, a configuration file containing the special character | May 28, 2021 | 6.5 | 22 | NO | NO |
CVE-2022-39837MEDIUM An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can b | Oct 25, 2022 | 5.5 | 20 | NO | NO |
CVE-2022-39836MEDIUM An issue was discovered in Connected Vehicle Systems Alliance (COVESA) dlt-daemon through 2.18.8. Due to a faulty DLT file parser, a crafted DLT file that crashes the process can b | Oct 25, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Genivi.
Media articles that mention a CVE ID that affects a product developed by Genivi — matched by CVE ID, not by vendor name.