Junglewise Threat Intelligence

CVE-2026-72124: Linux kernel isotp race condition in TX state transitions

CVE-2026-72124 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ISO-TP (ISO 15765-2) transport protocol handler contains a race condition in how it manages concurrent transmission state. An attacker could exploit concurrent access from multiple threads or timer callbacks to corrupt the state machine, potentially causing denial of service or packet corruption in CAN bus communication systems that rely on this protocol for reliable message delivery.

Technical details

The vulnerability is a synchronization bug in the CAN ISO-TP (can: isotp) subsystem where the TX state machine (so->tx.state) is accessed from three concurrent contexts—sendmsg(), RX frame processing, and hrtimer callbacks—without proper locking coordination. The root cause is that sendmsg() used a lock-free cmpxchg() to claim the TX state while hrtimer_cancel() calls elsewhere held so->rx_lock, creating windows where frames or timer callbacks could observe stale state and corrupt active transfers. The fix serializes the entire TX claim lifecycle under so->rx_lock, ensuring atomicity of state transitions and timer cancellation. This affects any system using CAN-bus ISO-TP communication; exploitation requires the ability to send concurrent messages or trigger timer races, which may be reachable via local unprivileged processes with access to CAN sockets.

Affected products

  • Linux Linux kernel versions prior to the fix commit

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched: Fix integrated into kernel; commit details not provided in advisory

Related threats