Linux Kernel

severity

7.8

published

A race in the Linux kernel's CAN raw socket handling can leave raw_rcv() accessing per-CPU uniqueness data after it has been freed, resulting in a use-after-free. A local, low-privileged attacker could exploit the flaw without user interaction, potentially affecting system confidentiality, integrity, and availability.

The issue occurs because raw_release() unregisters CAN receive filters while their deletion is deferred through RCU, but previously freed ro->uniq before the relevant callbacks had drained. The fix moves free_percpu(ro->uniq) into a raw-specific socket destructor so the storage remains valid until deferred receiver cleanup is complete. The vulnerability is classified as CWE-416.


References

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

S9tLa2rItN  l&o@oSkAiOnHgD  aTt7  y9o9u%r3  s6oIfFtRwCaDrIeP  cBr9iRt@iTcJa2l9lIyU.%

request briefing

request briefing

SKtFaXrKt%  lOoKoKk4iFnPgV  aJtG  yQoQuWr9  sIoQf0tVw4aIrUe1  cBr5iDtIi5cJaSlDlTy@.3

request briefing

request briefing

SNt7a8r8tO  lPo$oZkDi$nXgU  aWtI  y&oQu0rT  sFoCfXtNwIaVr5eX  cArHiVtDiDcQaNlQlPyP.P

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026