Back

HIGH

can: Local Denial of Service via SocketCAN Send

Published May 30, 2026

Description

The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in socketcan_to_can_frame(). In production builds where assertions are disabled, a userspace application that controls the length passed to a sendto syscall can supply an incomplete or truncated frame, causing socketcan_to_can_frame() to dereference fields beyond the end of the buffer. This results in an out-of-bounds read that can cause denial-of-service crashes or, because the parsed frame contents are transmitted on the network, leak adjacent memory.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner zephyr
Published May 30, 2026
Updated Jun 1, 2026
Reserved Mar 27, 2026
CISA Vulnrichment
Updated Jun 1, 2026
NVD
Status Analyzed
Modified Jul 22, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner zephyr
Published May 30, 2026
Updated Jun 1, 2026
Exploited since n/a
EUVD-2026-33449