Linux Kernel Vulnerability Affecting CAN ISOTP Implementation
CVE-2026-80889

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80889?

The Linux kernel contains a vulnerability within the CAN ISOTP implementation that impacts the proper handling of timer drain order, wakeup handling, and the ordering of transmission generation. A series of patches have addressed multiple issues, ensuring that the transmission state transitions are properly managed to avoid stale callbacks, incorrect shutdown handling, and the risk of that multiple threads interfering with concurrent operations. Specific changes include enhancements to the processing of send operations, ensuring state consistency, and management of errors, enhancing the overall reliability and security of CAN network communications.

Affected Version(s)

Linux bbedeb67a9a684f2fb78c55bd3662c400526715e < 8acab9fc66d6f426c36968c91a979f70784945a7

Linux 377a8f500704da42ed86a4541ed930e9dcfdb2ea

Linux 6da8119e8dd542194103139812d1a4b7dcd1aedd < 2753722612d8824d3910096f93059f669009b0f0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.