Junglewise Threat Intelligence

CVE-2026-80707: Linux kernel J1939 CAN transport uninitialized buffer information disclosure

CVE-2026-80707 · Severity: high · CVSS 7.5 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's SAE J1939 CAN protocol transport layer fails to zero-initialize allocated receive buffers in the j1939_session_fresh_new() function, potentially exposing sensitive kernel memory. An attacker with access to the CAN bus could read residual data from previously freed memory through improperly initialized buffers, compromising data confidentiality without requiring special privileges or user interaction.

Technical details

This vulnerability is an uninitialized buffer information disclosure in the J1939 extended transport protocol (ETP) session setup. The vulnerable function j1939_session_fresh_new() allocates a receive buffer via skb_put() but does not zero the allocated memory, leaving residual kernel data in place. An attacker with network access to a CAN bus can observe the uninitialized data in protocol frames. The root cause is the use of skb_put() instead of skb_put_zero() when allocating ETP buffers. The fix involves replacing a single function call to ensure allocated buffers are zeroed, applied in the stable kernel tree across multiple versions.

Affected products

  • Linux Linux kernel multiple versions (from 2.6.x through 6.x and 7.x branches affected)

Timeline

  • 2026-08-28: disclosed
  • 2026-08-09: patched

References

Related threats