Junglewise Threat Intelligence

CVE-2026-63990: Linux Kernel null pointer dereference in bonding driver via CAN devices

CVE-2026-63990 · Severity: info · CVSS 5.5 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's network bonding driver can cause a system crash. The issue occurs when the system incorrectly attempts to combine Controller Area Network (CAN) devices—typically used in automotive and industrial hardware—into a standard Ethernet-style bond. This mismatch in networking architectures leads to a system failure (kernel panic), potentially resulting in a denial of service for the affected machine.

Technical details

A vulnerability exists in the Linux kernel bonding driver (drivers/net/bonding/bond_main.c) due to improper validation of network device types during the enslavement process. When a virtual CAN device (vxcan) is enslaved to a bonding master, the driver attempts to modify the device state to fit an Ethernet aggregation model. Because CAN devices utilize a different Layer 2 architecture and rely on the 'can_ml_priv' data structure—which the bonding driver does not initialize—subsequent operations like closing sockets trigger a null-pointer dereference in 'can_rx_unregister()'. This issue is reachable locally and results in a kernel paging request crash (KASAN). The fix involves explicitly blocking devices of type ARPHRD_CAN in 'bond_enslave()'.

Affected products

  • Linux Linux Kernel cd05acfe65ed

Timeline

  • 2026-05-26: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats