7.1
CVE-2026-72116
- EPSS 0.18%
- Veröffentlicht 15.08.2026 05:52:56
- Zuletzt bearbeitet 19.08.2026 17:20:57
- Erkennungen
can: bcm: fix stale rx/tx ops after device removal
In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops after device removal RX: an RX_SETUP update(!) for an existing op skipped can_rx_register() unconditionally, even when a concurrent NETDEV_UNREGISTER had already torn down its registration (op->rx_reg_dev == NULL). This silently did not re-enable frame delivery for that updated filter. bcm_rx_setup() now re-registers in that case, while leaving rx_ops with ifindex = 0 (all CAN devices) which never carry a tracked rx_reg_dev registered as-is. TX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving tx_ops with an active cyclic transmission re-arming its hrtimer indefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer prevents the runaway timer and any injection into a later reused ifindex, since nothing else calls bcm_can_tx() for the op until an explicit TX_SETUP update re-arms it. Unlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops, the ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup() always rejects ifindex 0, so clearing it would strand the op: neither a later TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could ever find it again, since both require an exact ifindex match.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ffd980f976e7fd666c2e61bf8ab35107efd11828
Version <
d30a36066ed3abefb72ae18901f71841ba18b350
Status
affected
Version
ffd980f976e7fd666c2e61bf8ab35107efd11828
Version <
ca829677ffa2de5d79e06366e19ac1e4f5cc78dd
Status
affected
Version
ffd980f976e7fd666c2e61bf8ab35107efd11828
Version <
9517d8fb0b191398d35b9b7f8c719c1cc7761cb1
Status
affected
Version
ffd980f976e7fd666c2e61bf8ab35107efd11828
Version <
60d8a7942f4ed2d975207aaeba1adb576707e53d
Status
affected
Version
ffd980f976e7fd666c2e61bf8ab35107efd11828
Version <
f749e4564952d60e96930c09f2be99955d07c22e
Status
affected
Version
ffd980f976e7fd666c2e61bf8ab35107efd11828
Version <
6be3e1fedf03eab36a2c09d755d1171287b2014b
Status
affected
Version
ffd980f976e7fd666c2e61bf8ab35107efd11828
Version <
b31d0933509c5a35c0be5736a2ce8df0d1bf112c
Status
affected
Version
ffd980f976e7fd666c2e61bf8ab35107efd11828
Version <
3b762c0d950383ab7a002686c9136b9aa55d2d70
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.25
Status
affected
Version
0
Version <
2.6.25
Status
unaffected
Version <=
5.10.*
Version
5.10.265
Status
unaffected
Version <=
5.15.*
Version
5.15.216
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.148
Status
unaffected
Version <=
6.12.*
Version
6.12.101
Status
unaffected
Version <=
6.18.*
Version
6.18.42
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.08 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
https://git.kernel.org/stable/c/60d8a7942f4ed2d975207aaeba1adb576707e53d
https://git.kernel.org/stable/c/f749e4564952d60e96930c09f2be99955d07c22e
https://git.kernel.org/stable/c/6be3e1fedf03eab36a2c09d755d1171287b2014b
https://git.kernel.org/stable/c/b31d0933509c5a35c0be5736a2ce8df0d1bf112c
https://git.kernel.org/stable/c/3b762c0d950383ab7a002686c9136b9aa55d2d70
https://git.kernel.org/stable/c/9517d8fb0b191398d35b9b7f8c719c1cc7761cb1
https://git.kernel.org/stable/c/ca829677ffa2de5d79e06366e19ac1e4f5cc78dd
https://git.kernel.org/stable/c/d30a36066ed3abefb72ae18901f71841ba18b350