Vulnerability in the Linux Kernel Affecting CAN Device Bonding Functionality
CVE-2026-63990

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-63990?

This vulnerability arises when attempting to enslave virtual CAN devices to a bonding master within the Linux kernel. The bonding driver modifies network device states intended for Ethernet aggregation, leading to the potential for null-pointer dereference errors during socket operations due to improper handling of the CAN architecture. To mitigate this issue, an explicit check is implemented to prevent CAN devices from being enslaved, ensuring the integrity of the bonding architecture and preventing changes that could cause system instability or memory leaks.

Affected Version(s)

Linux cd05acfe65ed2cf2db683fa9a6adb8d35635263b < 69b78b5f3033272e53a2dc2dad675962654a5b38

Linux cd05acfe65ed2cf2db683fa9a6adb8d35635263b < 41e8478c4cd896d3abbe33d41afc90c84ac66602

Linux cd05acfe65ed2cf2db683fa9a6adb8d35635263b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.