Use-after-free in Linux kernel - CVE-2026-72125
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free race in the Linux kernel CAN ISO-TP socket handling in net/can/isotp.c when releasing a socket concurrently with NETDEV_UNREGISTER. A local user can trigger concurrent socket release and device unregistration to cause a denial of service.
The issue can leave a stale CAN filter referencing a freed socket.
Affected software
Ubuntu
linux-nvidia-tegra (Ubuntu package)
How to mitigate CVE-2026-72125
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1035.38
External References
- https://git.kernel.org/stable/c/0b811c4bbe3ec9ad611e90a540fe8b51b3bb8a96
- https://git.kernel.org/stable/c/20bab8b88baac140ca3701116e1d486c7f51e311
- https://git.kernel.org/stable/c/43884dc7963beef2328f507f4fe680bdc173eb80
- https://git.kernel.org/stable/c/7bef39ba76eb7307ed22a50329e0f5776dbeda58
- https://git.kernel.org/stable/c/e442b62ba5a7756c17e05a77b32cdd085a2b6138