Executive brief
A vulnerability in the Linux kernel's network bonding driver can cause a system crash. The issue occurs when the system incorrectly attempts to combine Controller Area Network (CAN) devices—typically used in automotive and industrial hardware—into a standard Ethernet-style bond. This mismatch in networking architectures leads to a system failure (kernel panic), potentially resulting in a denial of service for the affected machine.
Technical details
A vulnerability exists in the Linux kernel bonding driver (drivers/net/bonding/bond_main.c) due to improper validation of network device types during the enslavement process. When a virtual CAN device (vxcan) is enslaved to a bonding master, the driver attempts to modify the device state to fit an Ethernet aggregation model. Because CAN devices utilize a different Layer 2 architecture and rely on the 'can_ml_priv' data structure—which the bonding driver does not initialize—subsequent operations like closing sockets trigger a null-pointer dereference in 'can_rx_unregister()'. This issue is reachable locally and results in a kernel paging request crash (KASAN). The fix involves explicitly blocking devices of type ARPHRD_CAN in 'bond_enslave()'.
Affected products
- Linux Linux Kernel cd05acfe65ed
Timeline
- 2026-05-26: other: Patch authored
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/02f1c87ded33b43d48b4a1d665da15f2157b30d8
- https://git.kernel.org/stable/c/41e8478c4cd896d3abbe33d41afc90c84ac66602
- https://git.kernel.org/stable/c/563090e5d450c665f70d955a39f9587afc7842eb
- https://git.kernel.org/stable/c/69b78b5f3033272e53a2dc2dad675962654a5b38
- https://git.kernel.org/stable/c/8ba68464e4787b6a7ec938826e16124df20fd23d
- https://git.kernel.org/stable/c/9ea8a648d9120f7652bcde1ce2c4ad66871af707
- https://git.kernel.org/stable/c/f4d78a81f57df82e9d82a2c07471fed1a1235893