Junglewise Threat Intelligence

CVE-2026-72125: Linux kernel CAN isotp use-after-free in device unregistration

CVE-2026-72125 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's CAN isotp protocol implementation contains a use-after-free vulnerability in how it handles network device unregistration. When a network device is removed, a race condition can allow freed socket memory to still be referenced by CAN receive filters, potentially leading to kernel crashes or allowing an attacker to manipulate freed memory. This affects systems using CAN bus communication, commonly found in automotive and industrial control networks.

Technical details

The vulnerability is a use-after-free race condition in the isotp_release() function. During concurrent network device unregistration (NETDEV_UNREGISTER), isotp_release() could fail to find the bound device via dev_get_by_index() after it was unlisted from the ifindex hash but before notifier callbacks ran. This allowed the socket to be freed without properly unregistering its CAN receive filter, leaving a stale filter pointing to freed socket memory. The fix, modeled after raw.c, maintains a tracked reference to the bound net_device (so->dev/so->dev_tracker) from bind() onward and serializes bind()/release() operations with rtnl_lock() to ensure consistency. bind() now rejects rebinding while state is not ISOTP_IDLE to prevent timer-based race windows.

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2026-08-15: disclosed: CVE-2026-72125 published

Related threats