CVE-2026-31532Disclosure(linux / linux_kernel)

MEDIUMCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() raw_release() unregisters raw CAN receive filters via can_rx_unregister(), but receiver deletion is deferred with call_rcu(). This leaves a window where raw_rcv() may still be running in an RCU read-side critical section after raw_release() frees ro->uniq, leading to a use-after-free of the percpu uniq storage. Move free_percpu(ro->uniq) out of raw_release() and into a raw-specific socket destructor. can_rx_unregister() takes an extra reference to the socket and only drops it from the RCU callback, so freeing uniq from sk_destruct ensures the percpu area is not released until the relevant callbacks have drained. [mkl: applied manually]

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 4 mentions (2026-04-23); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
linux_kernel

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-04-23: 4Mentions · 2026-04-29: 1Mentions · 2026-05-08: 2Mentions · 2026-05-09: 1Mentions · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-09: 1Active Exploitation · 2026-04-23: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-05-08: 2Technical Details · 2026-04-23: 1Technical Details · 2026-05-08: 104-2304-2905-0805-0905-20
Signal classification4 categories
Disclosure
444.4%
General
333.3%
Active Exploitation
111.1%
Patch
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-234
Active Exploitation1General2Patch1
2026-04-291
Disclosure1
2026-05-082
Disclosure2
2026-05-091
Disclosure1
2026-05-201
General1
Full discourse9 posts
  • bynario@bynar_io
    Disclosure

    In the first of a three-part series, @sam4k1 does a technical deep dive on CVE-2026-31532: a race condition in the Linux kernel's SocketCAN subsystem discovered, validated, and patched by our pipeline. https://www.bynar.io/blog/discovery-validation-in-the-linux-kernel-part-1-can-use-after-free-race

    Post summary

    The post provides a technical analysis of CVE-2026-31532, detailing a race condition in the Linux kernel's SocketCAN subsystem and noting that a patch was applied by the pipeline.

    0152493415.0K
    250 followersView on X
  • bynario@bynar_io
    General

    To wrap-up the series, @sam4k1 puts local models running on a Mac Studio head-to-head with Opus 4.6 on the kernel bugs, CVE-2026-31532 & CVE-2026-31694, from parts 1 & 2. https://bynar.io/blog/discovery-validation-in-the-linux-kernel-part-3-local-vs-frontier-models/

    Post summary

    The post references kernel CVE-2026-31532 and CVE-2026-31694 and links to a blog, but provides no additional technical details, exploit code, or patch information.

    062323411.4K
    253 followersView on X
  • bynario@bynar_io
    Disclosure

    Our autonomous AI pipeline recently found and validated a vulnerability in the Linux kernel - now tracked as CVE-2026-31532. CAN code is used across automotive, industrial, and embedded stacks. Securing low-level, safety-critical environments like this is just one example of the work we believe matters. Technical write-up coming soon.

    Post summary

    The message announces the detection of a Linux kernel vulnerability, CVE-2026-31532, by an autonomous AI pipeline, but offers no PoC, exploit, or remediation details.

    1121244.9K
    250 followersView on X
  • Lorenzo Cavallaro@lcavallaro
    Disclosure

    Kudos to @sam4k1 for the write up of the CVE-2026-31532 Linux kernel CAN-related vulnerability we recently found, validated, and patched @bynar_io It's not just the CVE: it matters, but it's also about the importance of grounding models, orchestration and domain expertise.

    Post summary

    The tweet acknowledges the discovery and patching of CVE-2026-31532, a Linux kernel CAN‑related vulnerability, but provides no proof of concept, exploit details, or evidence of active exploitation.

    00092983
    1.8K followersView on X
  • Mounir IDRASSI@idrassi
    Disclosure

    New entry in Bugflation for @bynar_io following CVE-2026-31532. Excellent findings! https://bugflation.com/findings/cve-2026-31532-linux-can-bynario/

    Post summary

    The text announces a new Bugflation entry for CVE‑2026‑31532, praising its findings but without providing technical details, exploit code, or mitigation steps.

    0000097
    155 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Linux Kernel (CVE-2026-31532) https://vuldb.com/vuln/359131/cti

    Post summary

    The post reports that CVE‑2026‑31532 in the Linux Kernel is currently being actively exploited, but provides no PoC, exploit code, patch, or detailed technical information.

    0000068
    2.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31532 In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() raw_release() unregisters raw CAN receive fil… https://www.cve.org/CVERecord?id=CVE-2026-31532

    Post summary

    The Linux kernel use‑after‑free issue (CVE‑2026‑31532) has been fixed, and a CVE record is available.

    0000056
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-31532 In the Linux kernel, the following vulnerability has been resolve... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31532 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet simply links to a vulnerability details page for CVE-2026-31532 without providing additional technical, PoC, exploit, patch, or exploitation information.

    0000047
    4.0K followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-31532) https://vuldb.com/vuln/359131

    Post summary

    A new critical Linux kernel CVE (CVE-2026-31532) was announced, but the text provides no technical details, PoC, exploit code, or patch information.

    0000060
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---

Explore more