Executive brief
The Linux kernel's SAE J1939 CAN protocol transport layer fails to zero-initialize allocated receive buffers in the j1939_session_fresh_new() function, potentially exposing sensitive kernel memory. An attacker with access to the CAN bus could read residual data from previously freed memory through improperly initialized buffers, compromising data confidentiality without requiring special privileges or user interaction.
Technical details
This vulnerability is an uninitialized buffer information disclosure in the J1939 extended transport protocol (ETP) session setup. The vulnerable function j1939_session_fresh_new() allocates a receive buffer via skb_put() but does not zero the allocated memory, leaving residual kernel data in place. An attacker with network access to a CAN bus can observe the uninitialized data in protocol frames. The root cause is the use of skb_put() instead of skb_put_zero() when allocating ETP buffers. The fix involves replacing a single function call to ensure allocated buffers are zeroed, applied in the stable kernel tree across multiple versions.
Affected products
- Linux Linux kernel multiple versions (from 2.6.x through 6.x and 7.x branches affected)
Timeline
- 2026-08-28: disclosed
- 2026-08-09: patched