PT-2026-34922 · Linux · Linux Kernel

Published

2026-04-24

·

Updated

2026-05-09

·

CVE-2026-31570

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds heap access exists in the cgw csum crc8 rel() function. Although the function calculates bounds-safe indices using calc idx(), it incorrectly uses raw signed 8-bit fields for the loop and result write. This allows reading and writing to memory locations before the start of the canfd frame on the heap when negative indices are provided. This issue was confirmed using KASAN on version 7.0-rc2.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2026-31570
ECHO-C8E1-F524-CF55
OESA-2026-2234

Affected Products

Linux Kernel