{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-31570", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2026-03-09T15:48:24.117Z", "datePublished": "2026-04-24T14:35:49.435Z", "dateUpdated": "2026-08-05T12:23:34.970Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:23:34.970Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: gw: fix OOB heap access in cgw_csum_crc8_rel()\n\ncgw_csum_crc8_rel() correctly computes bounds-safe indices via calc_idx():\n\n int from = calc_idx(crc8->from_idx, cf->len);\n int to = calc_idx(crc8->to_idx, cf->len);\n int res = calc_idx(crc8->result_idx, cf->len);\n\n if (from < 0 || to < 0 || res < 0)\n return;\n\nHowever, the loop and the result write then use the raw s8 fields directly\ninstead of the computed variables:\n\n for (i = crc8->from_idx; ...) /* BUG: raw negative index */\n cf->data[crc8->result_idx] = ...; /* BUG: raw negative index */\n\nWith from_idx = to_idx = result_idx = -64 on a 64-byte CAN FD frame,\ncalc_idx(-64, 64) = 0 so the guard passes, but the loop iterates with\ni = -64, reading cf->data[-64], and the write goes to cf->data[-64].\nThis write might end up to 56 (7.0-rc) or 40 (<= 6.19) bytes before the\nstart of the canfd_frame on the heap.\n\nThe companion function cgw_csum_xor_rel() uses `from`/`to`/`res`\ncorrectly throughout; fix cgw_csum_crc8_rel() to match.\n\nConfirmed with KASAN on linux-7.0-rc2:\n BUG: KASAN: slab-out-of-bounds in cgw_csum_crc8_rel+0x515/0x5b0\n Read of size 1 at addr ffff8880076619c8 by task poc_cgw_oob/62\n\nTo configure the can-gw crc8 checksums CAP_NET_ADMIN is needed." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 8.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:A - The vulnerable function runs in the CAN gateway receive path for CAN/CAN FD frames, after a matching gateway rule processes traffic. In a reasonable automotive or industrial CAN gateway deployment, an attacker on the same CAN segment can send matching CAN FD frames, so this is Adjacent.\nAC:L - There is no race or probabilistic condition; once an affected CRC8 relative-index gateway rule exists, the attacker can choose CAN ID, payload length, and frame contents to trigger the bad negative index path reliably. A 64-byte CAN FD frame reaches the demonstrated OOB case directly.\nPR:N - No host privileges are required to inject trigger CAN FD traffic into an already configured gateway route on the CAN segment. Creating or changing the rule requires CAP_NET_ADMIN in init_user_ns, but the highest reasonable deployed gateway scenario only requires attacker-controlled bus traffic.\nUI:N - No victim user action is required after the affected gateway configuration is present. The vulnerable code runs automatically while processing matching CAN FD frames.\nS:U - The impact is within the same kernel security authority as the vulnerable CAN gateway code. This is not a VM escape, IOMMU bypass, or other cross-scope boundary violation.\nC:H - The bug performs out-of-bounds heap reads before the CAN FD frame while computing CRC8. Because this is kernel heap memory exposure potential from memory corruption, confidentiality impact is High.\nI:H - The bug performs an out-of-bounds heap write through cf->data[result_idx] using a raw negative index. Kernel heap corruption is defensibly exploitable for integrity compromise, so integrity impact is High.\nA:H - KASAN confirms a slab-out-of-bounds access in the receive path, and repeated crafted frames can trigger kernel memory corruption. This can crash or destabilize the kernel, so availability impact is High." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/can/gw.c" ], "versions": [ { "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb", "lessThan": "e7c99348b0612b2bc02d5ce6ff9873261cc7605f", "status": "affected", "versionType": "git" }, { "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb", "lessThan": "999ca48d55a8a46da21519db7e834e5867200379", "status": "affected", "versionType": "git" }, { "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb", "lessThan": "a025283d7f7404c739225e457fb99db2368bb544", "status": "affected", "versionType": "git" }, { "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb", "lessThan": "54ecdf76a55e75c1f5085e440f8ab671a3283ef5", "status": "affected", "versionType": "git" }, { "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb", "lessThan": "c4e8eaa75fa0b6bcbfa5356d6195c4ad0e05e57a", "status": "affected", "versionType": "git" }, { "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb", "lessThan": "84f8b76d24273175a22713e83e90874e1880d801", "status": "affected", "versionType": "git" }, { "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb", "lessThan": "66b689efd08227da2c5ca49b58b30a95d23c695a", "status": "affected", "versionType": "git" }, { "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb", "lessThan": "b9c310d72783cc2f30d103eed83920a5a29c671a", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/can/gw.c" ], "versions": [ { "version": "5.4", "status": "affected" }, { "version": "0", "lessThan": "5.4", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.253", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.203", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.168", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.131", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.80", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.18.21", "lessThanOrEqual": "6.18.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.19.11", "lessThanOrEqual": "6.19.*", "status": "unaffected", "versionType": "semver" }, { "version": "7.0", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "5.10.253" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "5.15.203" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.1.168" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.6.131" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.12.80" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.18.21" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "6.19.11" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4", "versionEndExcluding": "7.0" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/e7c99348b0612b2bc02d5ce6ff9873261cc7605f" }, { "url": "https://git.kernel.org/stable/c/999ca48d55a8a46da21519db7e834e5867200379" }, { "url": "https://git.kernel.org/stable/c/a025283d7f7404c739225e457fb99db2368bb544" }, { "url": "https://git.kernel.org/stable/c/54ecdf76a55e75c1f5085e440f8ab671a3283ef5" }, { "url": "https://git.kernel.org/stable/c/c4e8eaa75fa0b6bcbfa5356d6195c4ad0e05e57a" }, { "url": "https://git.kernel.org/stable/c/84f8b76d24273175a22713e83e90874e1880d801" }, { "url": "https://git.kernel.org/stable/c/66b689efd08227da2c5ca49b58b30a95d23c695a" }, { "url": "https://git.kernel.org/stable/c/b9c310d72783cc2f30d103eed83920a5a29c671a" } ], "title": "can: gw: fix OOB heap access in cgw_csum_crc8_rel()", "x_generator": { "engine": "bippy-1.2.0" } } } }