PT-2026-34379 · Linux+3 · Linux Kernel+3

CVE-2026-31474

·

Publicado

2026-04-22

·

Atualizado

2026-08-30

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (versões afetadas não especificadas)
Description Um problema de use-after-free existe na função isotp sendmsg(). A função utiliza cmpxchg() em so->tx.state para serializar o acesso ao so->tx.buf. Quando isotp release() aguarda por ISOTP IDLE via wait event interruptible(), um sinal pode interromper este processo durante uma operação de close() enquanto tx.state está em ISOTP SENDING. Isso faz com que o loop termine prematuramente, levando o processo de liberação a forçar ISOTP SHUTDOWN e chamar kfree(so->tx.buf) enquanto isotp fill dataframe() ainda pode estar lendo so->tx.buf para o quadro CAN final.
Recommendations No momento, não há informações sobre uma versão mais recente que contenha a correção para esta vulnerabilidade.

Exploit

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2026:27288
ALSA-2026:27789
AZL-83225
CVE-2026-31474
OPENSUSE-SU-2026:21555-1
RHSA-2026:27288
RHSA-2026:27731
RHSA-2026:27789
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1
USN-8665-1

Produtos afetados

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu