Executive brief
The Linux kernel's ISO-TP (ISO 15765-2) transport protocol handler contains a race condition in how it manages concurrent transmission state. An attacker could exploit concurrent access from multiple threads or timer callbacks to corrupt the state machine, potentially causing denial of service or packet corruption in CAN bus communication systems that rely on this protocol for reliable message delivery.
Technical details
The vulnerability is a synchronization bug in the CAN ISO-TP (can: isotp) subsystem where the TX state machine (so->tx.state) is accessed from three concurrent contexts—sendmsg(), RX frame processing, and hrtimer callbacks—without proper locking coordination. The root cause is that sendmsg() used a lock-free cmpxchg() to claim the TX state while hrtimer_cancel() calls elsewhere held so->rx_lock, creating windows where frames or timer callbacks could observe stale state and corrupt active transfers. The fix serializes the entire TX claim lifecycle under so->rx_lock, ensuring atomicity of state transitions and timer cancellation. This affects any system using CAN-bus ISO-TP communication; exploitation requires the ability to send concurrent messages or trigger timer races, which may be reachable via local unprivileged processes with access to CAN sockets.
Affected products
- Linux Linux kernel versions prior to the fix commit
Timeline
- 2026-08-15: disclosed
- 2026-08-15: patched: Fix integrated into kernel; commit details not provided in advisory