« Volver al listado

CVE-2026-72126

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

can: isotp: use unconditional synchronize_rcu() in isotp_release()

isotp_notify() unregisters the (RCU) CAN filters via can_rx_unregister() and clears so->bound without waiting for a grace period. isotp_release() uses so->bound to decide whether it needs to call synchronize_rcu() before cancelling so->rxtimer, so when NETDEV_UNREGISTER runs first it skips that synchronize_rcu() and can cancel the timer while an in-flight isotp_rcv() is still executing and about to re-arm it via isotp_send_fc(), leading to a use-after-free timer callback on the freed socket.

Leer descripción completaMostrar menos

sakisho-bot remarked a problem with rtnl_lock held in isotp_notify(), therefore make isotp_release() always call synchronize_rcu() before cancelling the timers, regardless of so->bound. This still closes the original race (isotp_notify() clearing so->bound without waiting for in-flight isotp_rcv() callers before isotp_release() cancels the RX timer) without adding any RCU wait to the netdevice notifier path.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L) con PR:L sin interacción: T1068. Use-after-free en timer RCU permite DoS o corrupción de memoria; impactos: denegación de servicio (crash/panic del kernel) y potencial escalada via corrupción de memoria.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72126",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "22bfa94db2ef6900c790884fa9461486516626e9",
              "lessThan": "945d9894502cd9124f5d676181c542ed2000f7c0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "14a4696bc3118ba49da28f79280e1d55603aa737",
              "lessThan": "59672aa4bcd8d32172c1ff6a179583981d6acabc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "14a4696bc3118ba49da28f79280e1d55603aa737",
              "lessThan": "15413a082df69175c2f96aeab4c26fe1ff7cff03",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "14a4696bc3118ba49da28f79280e1d55603aa737",
              "lessThan": "6280eda96e0707264849fa7d036fed873c1f8a6d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "14a4696bc3118ba49da28f79280e1d55603aa737",
              "lessThan": "cb6abc584a1bfab107ac003d64948a4aef1730aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "14a4696bc3118ba49da28f79280e1d55603aa737",
              "lessThan": "b88a511308779c225005d7994b8744561bdbafbc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "14a4696bc3118ba49da28f79280e1d55603aa737",
              "lessThan": "b8278ff605187ef3fa0f2705e93251cce4c4f8ee",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "14a4696bc3118ba49da28f79280e1d55603aa737",
              "lessThan": "9b1a02e0d980ac6b0e36a90378f847062f81d7e4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80c6ddf771df2ef786f28c1ca5919b3f1080091b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ebf91625b3e404bd2b4b694c7ee71c1e8f8bd08f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.50",
              "lessThan": "5.10.261",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.12.17",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.13.2",
              "lessThan": "5.14",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/can/isotp.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/can/isotp.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:29.963",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/15413a082df69175c2f96aeab4c26fe1ff7cff03",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/59672aa4bcd8d32172c1ff6a179583981d6acabc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6280eda96e0707264849fa7d036fed873c1f8a6d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/945d9894502cd9124f5d676181c542ed2000f7c0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b1a02e0d980ac6b0e36a90378f847062f81d7e4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b8278ff605187ef3fa0f2705e93251cce4c4f8ee",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b88a511308779c225005d7994b8744561bdbafbc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb6abc584a1bfab107ac003d64948a4aef1730aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: use unconditional synchronize_rcu() in isotp_release()\n\nisotp_notify() unregisters the (RCU) CAN filters via can_rx_unregister()\nand clears so->bound without waiting for a grace period. isotp_release()\nuses so->bound to decide whether it needs to call synchronize_rcu()\nbefore cancelling so->rxtimer, so when NETDEV_UNREGISTER runs first it\nskips that synchronize_rcu() and can cancel the timer while an\nin-flight isotp_rcv() is still executing and about to re-arm it via\nisotp_send_fc(), leading to a use-after-free timer callback on the\nfreed socket.\n\nsakisho-bot remarked a problem with rtnl_lock held in isotp_notify(),\ntherefore make isotp_release() always call synchronize_rcu() before\ncancelling the timers, regardless of so->bound. This still closes the\noriginal race (isotp_notify() clearing so->bound without waiting for\nin-flight isotp_rcv() callers before isotp_release() cancels the RX\ntimer) without adding any RCU wait to the netdevice notifier path."
    }
  ],
  "lastModified": "2026-08-17T06:18:12.213",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}