{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-31570",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-03-09T15:48:24.117Z",
        "datePublished": "2026-04-24T14:35:49.435Z",
        "dateUpdated": "2026-08-05T12:23:34.970Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:23:34.970Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: gw: fix OOB heap access in cgw_csum_crc8_rel()\n\ncgw_csum_crc8_rel() correctly computes bounds-safe indices via calc_idx():\n\n    int from = calc_idx(crc8->from_idx, cf->len);\n    int to   = calc_idx(crc8->to_idx,   cf->len);\n    int res  = calc_idx(crc8->result_idx, cf->len);\n\n    if (from < 0 || to < 0 || res < 0)\n        return;\n\nHowever, the loop and the result write then use the raw s8 fields directly\ninstead of the computed variables:\n\n    for (i = crc8->from_idx; ...)        /* BUG: raw negative index */\n    cf->data[crc8->result_idx] = ...;    /* BUG: raw negative index */\n\nWith from_idx = to_idx = result_idx = -64 on a 64-byte CAN FD frame,\ncalc_idx(-64, 64) = 0 so the guard passes, but the loop iterates with\ni = -64, reading cf->data[-64], and the write goes to cf->data[-64].\nThis write might end up to 56 (7.0-rc) or 40 (<= 6.19) bytes before the\nstart of the canfd_frame on the heap.\n\nThe companion function cgw_csum_xor_rel() uses `from`/`to`/`res`\ncorrectly throughout; fix cgw_csum_crc8_rel() to match.\n\nConfirmed with KASAN on linux-7.0-rc2:\n  BUG: KASAN: slab-out-of-bounds in cgw_csum_crc8_rel+0x515/0x5b0\n  Read of size 1 at addr ffff8880076619c8 by task poc_cgw_oob/62\n\nTo configure the can-gw crc8 checksums CAP_NET_ADMIN is needed."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:A - The vulnerable function runs in the CAN gateway receive path for CAN/CAN FD frames, after a matching gateway rule processes traffic. In a reasonable automotive or industrial CAN gateway deployment, an attacker on the same CAN segment can send matching CAN FD frames, so this is Adjacent.\nAC:L - There is no race or probabilistic condition; once an affected CRC8 relative-index gateway rule exists, the attacker can choose CAN ID, payload length, and frame contents to trigger the bad negative index path reliably. A 64-byte CAN FD frame reaches the demonstrated OOB case directly.\nPR:N - No host privileges are required to inject trigger CAN FD traffic into an already configured gateway route on the CAN segment. Creating or changing the rule requires CAP_NET_ADMIN in init_user_ns, but the highest reasonable deployed gateway scenario only requires attacker-controlled bus traffic.\nUI:N - No victim user action is required after the affected gateway configuration is present. The vulnerable code runs automatically while processing matching CAN FD frames.\nS:U - The impact is within the same kernel security authority as the vulnerable CAN gateway code. This is not a VM escape, IOMMU bypass, or other cross-scope boundary violation.\nC:H - The bug performs out-of-bounds heap reads before the CAN FD frame while computing CRC8. Because this is kernel heap memory exposure potential from memory corruption, confidentiality impact is High.\nI:H - The bug performs an out-of-bounds heap write through cf->data[result_idx] using a raw negative index. Kernel heap corruption is defensibly exploitable for integrity compromise, so integrity impact is High.\nA:H - KASAN confirms a slab-out-of-bounds access in the receive path, and repeated crafted frames can trigger kernel memory corruption. This can crash or destabilize the kernel, so availability impact is High."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/can/gw.c"
                    ],
                    "versions": [
                        {
                            "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb",
                            "lessThan": "e7c99348b0612b2bc02d5ce6ff9873261cc7605f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb",
                            "lessThan": "999ca48d55a8a46da21519db7e834e5867200379",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb",
                            "lessThan": "a025283d7f7404c739225e457fb99db2368bb544",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb",
                            "lessThan": "54ecdf76a55e75c1f5085e440f8ab671a3283ef5",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb",
                            "lessThan": "c4e8eaa75fa0b6bcbfa5356d6195c4ad0e05e57a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb",
                            "lessThan": "84f8b76d24273175a22713e83e90874e1880d801",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb",
                            "lessThan": "66b689efd08227da2c5ca49b58b30a95d23c695a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "456a8a646b2563438c16a9b27decf9aa717f1ebb",
                            "lessThan": "b9c310d72783cc2f30d103eed83920a5a29c671a",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/can/gw.c"
                    ],
                    "versions": [
                        {
                            "version": "5.4",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.4",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.253",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.203",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.168",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.131",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.80",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.21",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.19.11",
                            "lessThanOrEqual": "6.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "5.10.253"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "5.15.203"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "6.1.168"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "6.6.131"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "6.12.80"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "6.18.21"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "6.19.11"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4",
                                    "versionEndExcluding": "7.0"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/e7c99348b0612b2bc02d5ce6ff9873261cc7605f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/999ca48d55a8a46da21519db7e834e5867200379"
                },
                {
                    "url": "https://git.kernel.org/stable/c/a025283d7f7404c739225e457fb99db2368bb544"
                },
                {
                    "url": "https://git.kernel.org/stable/c/54ecdf76a55e75c1f5085e440f8ab671a3283ef5"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c4e8eaa75fa0b6bcbfa5356d6195c4ad0e05e57a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/84f8b76d24273175a22713e83e90874e1880d801"
                },
                {
                    "url": "https://git.kernel.org/stable/c/66b689efd08227da2c5ca49b58b30a95d23c695a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b9c310d72783cc2f30d103eed83920a5a29c671a"
                }
            ],
            "title": "can: gw: fix OOB heap access in cgw_csum_crc8_rel()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}