๐Ÿ” CVE Alert

CVE-2026-31532

UNKNOWN 0.0

can: raw: fix ro->uniq use-after-free in raw_rcv()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() raw_release() unregisters raw CAN receive filters via can_rx_unregister(), but receiver deletion is deferred with call_rcu(). This leaves a window where raw_rcv() may still be running in an RCU read-side critical section after raw_release() frees ro->uniq, leading to a use-after-free of the percpu uniq storage. Move free_percpu(ro->uniq) out of raw_release() and into a raw-specific socket destructor. can_rx_unregister() takes an extra reference to the socket and only drops it from the RCU callback, so freeing uniq from sk_destruct ensures the percpu area is not released until the relevant callbacks have drained. [mkl: applied manually]

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Apr 23, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 572f0bf536ebc14f6e7da3d21a85cf076de8358e 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1a0f2de81f7fbdc538fc72d7d74609b79bc83cc0 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7201a531b9a5ed892bfda5ded9194ef622de8ffa 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 34c1741254ff972e8375faf176678a248826fe3a
Linux / Linux
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/572f0bf536ebc14f6e7da3d21a85cf076de8358e git.kernel.org: https://git.kernel.org/stable/c/1a0f2de81f7fbdc538fc72d7d74609b79bc83cc0 git.kernel.org: https://git.kernel.org/stable/c/7201a531b9a5ed892bfda5ded9194ef622de8ffa git.kernel.org: https://git.kernel.org/stable/c/34c1741254ff972e8375faf176678a248826fe3a