Linux Kernel

severity

7.8

published

A race in the Linux kernel's CAN raw socket handling can leave raw_rcv() accessing per-CPU uniqueness data after it has been freed, resulting in a use-after-free. A local, low-privileged attacker could exploit the flaw without user interaction, potentially affecting system confidentiality, integrity, and availability.

The issue occurs because raw_release() unregisters CAN receive filters while their deletion is deferred through RCU, but previously freed ro->uniq before the relevant callbacks had drained. The fix moves free_percpu(ro->uniq) into a raw-specific socket destructor so the storage remains valid until deferred receiver cleanup is complete. The vulnerability is classified as CWE-416.


References

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1

7.8

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

S5tAaMr5t0  l4o#oTkKi#n0gM  aOtY  yHo2uHr&  sRoEfUtXwEa1r3e2  cQr4iUtJi4c1aJl$lMyF.V

request briefing

request briefing

S1t7aOr2tR  lFo$oIkXiSn@gB  a5tM  yKo9uErG  s#oQf6t7w6aGrMeX  cCr3iStAiOc#aDlOl9yV.J

request briefing

request briefing

SGt&aUrGt8  l1oZo#kFiNn2gJ  aCtI  y9o0uLrP  s6oCfUtVwRaLrEeI  c7rFiAtCi2cDaJl2l#y4.P

request briefing

request briefing

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026

BYNARIO s.r.l. | PIAZZA BORROMEO 12, 20129 MILAN, ITALY | VAT- IT14434720968

all rights reserved

2026