Firmware Record Validation Flaw in Linux Kernel Affects Softing CAN Products
CVE-2026-80706

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80706?

A vulnerability exists in the Linux kernel within the Softing CAN framework. The issue arises from the fw_parse() function, which improperly handles firmware records by lacking knowledge of the firmware blob's end. This flaw allows potential out-of-bounds reads, which may lead to vulnerabilities in writing to Dynamic Programmable Read-Only Memory (DPRAM) due to inadequate bounds checking. The failure to validate the entire source record and the use of wrap-prone arithmetic poses risks during the firmware loading process. Developers are encouraged to pass the firmware end to the parser and implement strict validation checks to maintain system integrity.

Affected Version(s)

Linux 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c

Linux 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c < 84c850b08fc0d671c245144b619683129b55690a

Linux 03fd3cf5a179da12e6bee5e9d74b648aff68dc4c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.