7.8

CVE-2026-72125

can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER

In the Linux kernel, the following vulnerability has been resolved:

can: isotp: fix use-after-free race with concurrent NETDEV_UNREGISTER

isotp_release() looked up the bound network device via dev_get_by_index()
using the stored ifindex. During device unregistration the device is
unlisted from the ifindex hash before the NETDEV_UNREGISTER notifier
chain runs, so a concurrent isotp_release() could find no device, skip
can_rx_unregister() entirely, and still proceed to free the socket.
Since isotp_release() had already removed itself from the isotp
notifier list at that point, isotp_notify() would never get a chance to
clean up either, leaving a stale CAN filter that keeps pointing at the
freed socket.

Fix this the same way raw.c already does: hold a tracked reference to
the bound net_device in the socket (so->dev/so->dev_tracker) from
bind() onward instead of re-resolving it from the ifindex, and
serialize bind()/release() with rtnl_lock() so that so->dev is always
consistent with what the NETDEV_UNREGISTER notifier sees. so->dev
stays valid regardless of ifindex-hash unlisting, and is only ever
cleared by whichever of isotp_release()/isotp_notify() gets there
first, so the filter is always removed exactly once.

isotp_bind() now rejects a (re)bind with -EAGAIN while so->[tx|rx].state
isn't ISOTP_IDLE yet, so a timer left running by a prior
NETDEV_UNREGISTER can't act on a newly bound so->ifindex. Both checks
share the same lock_sock() section, so there is no window in which a
concurrent isotp_notify() clearing so->bound could be missed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e057dd3fc20ffb3d7f150af46542a51b59b90127
Version < f311bbb29bb06aaab69ba45a6e4b11323d20b8f9
Status affected
Version e057dd3fc20ffb3d7f150af46542a51b59b90127
Version < 8e018f4335590460ebcf0c2b493ed38ba1a35204
Status affected
Version e057dd3fc20ffb3d7f150af46542a51b59b90127
Version < 33b9cd9245e2a4b800f99ed1cc53d64960614152
Status affected
Version e057dd3fc20ffb3d7f150af46542a51b59b90127
Version < 0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96
Status affected
Version e057dd3fc20ffb3d7f150af46542a51b59b90127
Version < 43884dc7963beef2328f507f4fe680bdc173eb80
Status affected
Version e057dd3fc20ffb3d7f150af46542a51b59b90127
Version < 7bef39ba76eb7307ed22a50329e0f5776dbeda58
Status affected
Version e057dd3fc20ffb3d7f150af46542a51b59b90127
Version < e442b62ba5a7756c17e05a77b32cdd085a2b6138
Status affected
Version e057dd3fc20ffb3d7f150af46542a51b59b90127
Version < 20bab8b88baac140ca3701116e1d486c7f51e311
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.056
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96
https://git.kernel.org/stable/c/43884dc7963beef2328f507f4fe680bdc173eb80
https://git.kernel.org/stable/c/7bef39ba76eb7307ed22a50329e0f5776dbeda58
https://git.kernel.org/stable/c/e442b62ba5a7756c17e05a77b32cdd085a2b6138
https://git.kernel.org/stable/c/20bab8b88baac140ca3701116e1d486c7f51e311
https://git.kernel.org/stable/c/33b9cd9245e2a4b800f99ed1cc53d64960614152
https://git.kernel.org/stable/c/8e018f4335590460ebcf0c2b493ed38ba1a35204
https://git.kernel.org/stable/c/f311bbb29bb06aaab69ba45a6e4b11323d20b8f9