Executive brief
A security vulnerability has been identified in the Linux kernel's CAN networking protocol, which is commonly used in automotive and industrial systems. A local attacker could exploit a race condition to cause a system crash or potentially execute unauthorized code by triggering a memory error during network communication. This issue affects the reliability and security of systems relying on CAN bus messaging.
Technical details
A use-after-free (UAF) vulnerability exists in net/can/isotp.c within the isotp_sendmsg() function. The root cause is a race condition where isotp_release() can proceed to kfree(so->tx.buf) if a signal interrupts wait_event_interruptible() while the socket state is ISOTP_SENDING. This allows the buffer to be freed while isotp_fill_dataframe() is still reading it for transmission. The fix involves moving the buffer deallocation to the socket's destructor (sk_destruct) to ensure all operations are complete before memory is reclaimed. An attacker with local access can exploit this to cause a kernel panic or potentially achieve local privilege escalation.
Affected products
- Linux Linux Kernel Fixed in 6.1.x, 6.6.x, 6.7.x, 6.8.x, and mainline
- Red Hat Enterprise Linux 9/10
Timeline
- 2026-03-19: patched: Initial patch authored by Oliver Hartkopp
- 2026-04-22: advisory: CVE-2026-31474 published by NVD
References
- https://git.kernel.org/stable/c/2e62e7051eca75a7f2e3d52d62ec10d7d7aa358c
- https://git.kernel.org/stable/c/424e95d62110cdbc8fd12b40918f37e408e35a92
- https://git.kernel.org/stable/c/9649d051e54413049c009638ec1dc23962c884a4
- https://git.kernel.org/stable/c/cb3d6efa78460e6d50bf68806d0db66265709f64
- https://git.kernel.org/stable/c/eec8a1b18a79600bd4419079dc0026c1db72a830
- https://access.redhat.com/errata/RHSA-2026:27288
- https://access.redhat.com/errata/RHSA-2026:27731