Junglewise Threat Intelligence

CVE-2026-31474: Linux Kernel use-after-free in CAN ISOTP isotp_sendmsg

CVE-2026-31474 · Severity: high · CVSS 7.8 · Published 2026-04-22

Technologies: Linux Kernel, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9. Vendors: Red Hat, Linux.

Executive brief

A security vulnerability has been identified in the Linux kernel's CAN networking protocol, which is commonly used in automotive and industrial systems. A local attacker could exploit a race condition to cause a system crash or potentially execute unauthorized code by triggering a memory error during network communication. This issue affects the reliability and security of systems relying on CAN bus messaging.

Technical details

A use-after-free (UAF) vulnerability exists in net/can/isotp.c within the isotp_sendmsg() function. The root cause is a race condition where isotp_release() can proceed to kfree(so->tx.buf) if a signal interrupts wait_event_interruptible() while the socket state is ISOTP_SENDING. This allows the buffer to be freed while isotp_fill_dataframe() is still reading it for transmission. The fix involves moving the buffer deallocation to the socket's destructor (sk_destruct) to ensure all operations are complete before memory is reclaimed. An attacker with local access can exploit this to cause a kernel panic or potentially achieve local privilege escalation.

Affected products

  • Linux Linux Kernel Fixed in 6.1.x, 6.6.x, 6.7.x, 6.8.x, and mainline
  • Red Hat Enterprise Linux 9/10

Timeline

  • 2026-03-19: patched: Initial patch authored by Oliver Hartkopp
  • 2026-04-22: advisory: CVE-2026-31474 published by NVD

References

Related threats