Firmware Record Validation Flaw in Linux Kernel Affects Softing CAN Products
CVE-2026-80706
What is CVE-2026-80706?
A vulnerability exists in the Linux kernel within the Softing CAN framework. The issue arises from the fw_parse() function, which improperly handles firmware records by lacking knowledge of the firmware blob's end. This flaw allows potential out-of-bounds reads, which may lead to vulnerabilities in writing to Dynamic Programmable Read-Only Memory (DPRAM) due to inadequate bounds checking. The failure to validate the entire source record and the use of wrap-prone arithmetic poses risks during the firmware loading process. Developers are encouraged to pass the firmware end to the parser and implement strict validation checks to maintain system integrity.
Affected Version(s)
Linux 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c
Linux 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c < 84c850b08fc0d671c245144b619683129b55690a
Linux 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c