7.8
CVE-2026-72123
- EPSS 0.16%
- Veröffentlicht 15.08.2026 05:53:01
- Zuletzt bearbeitet 19.08.2026 17:20:59
- Erkennungen
can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
In the Linux kernel, the following vulnerability has been resolved:
can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF
Commit f1b4e32aca08 ("can: bcm: use call_rcu() instead of costly
synchronize_rcu()") replaced synchronize_rcu() in bcm_delete_rx_op()
with call_rcu() and introduced the RX_NO_AUTOTIMER flag.
However, this flag check was omitted for thrtimer in the packet rx
fast-path. During BCM RX operation teardown, a concurrent RCU reader
(bcm_rx_handler) can race and re-arm thrtimer via
bcm_rx_update_and_send() after call_rcu() has been scheduled. Once
the RCU grace period elapses, bcm_op is freed. The subsequently
firing thrtimer then dereferences the deallocated op, causing a UAF.
Adding flag checks to the rx fast-path (bcm_rx_update_and_send) does not
fully close the TOCTOU race and introduces latency for every CAN frame.
Conversely, calling hrtimer_cancel() directly inside the RCU callback
(softirq context) is fatal as hrtimer_cancel() can sleep, triggering
a "scheduling while atomic" panic.
Resolve this by deferring the timer cancellation and memory free to a
dedicated unbound workqueue (bcm_wq). The RCU callback now queues a
work item to bcm_wq, which safely cancels both timers and deallocates
memory in sleepable process context. A dedicated workqueue is used to
prevent system-wide WQ saturation and is cleanly flushed/destroyed
on module unload to avoid rmmod page faults.
Since the deferred work can now outlive the calling context by an
unbounded amount, also take a reference on op->sk when it is assigned
and drop it only once the deferred work has cancelled both timers, so a
socket can no longer be freed out from under a still-armed timer whose
callback (bcm_send_to_user()) dereferences op->sk.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
85cd41070df992d3c0dfd828866fdd243d3b774a
Version <
de5fce46637de05bef56ec08528127676eb6fc9b
Status
affected
Version
f34f2a18e47b73e48f90a757e1f4aaa8c7d665a1
Version <
036a8c320ca11bc912e8027adcfad14b326f067e
Status
affected
Version
f1b4e32aca0811aa011c76e5d6cf2fa19224b386
Version <
3cf4fd5316f449811d8baf1bc6978ef5a7b743a9
Status
affected
Version
f1b4e32aca0811aa011c76e5d6cf2fa19224b386
Version <
4177762f70646ac48a2af382e45a795cbd295198
Status
affected
Version
f1b4e32aca0811aa011c76e5d6cf2fa19224b386
Version <
6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f
Status
affected
Version
f1b4e32aca0811aa011c76e5d6cf2fa19224b386
Version <
cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5
Status
affected
Version
f1b4e32aca0811aa011c76e5d6cf2fa19224b386
Version <
ce2d4b121fb7545e1ed588e860c8e5fd5ad45224
Status
affected
Version
f1b4e32aca0811aa011c76e5d6cf2fa19224b386
Version <
68973f9db76144825e4f35dfdc80fb8279eb2d57
Status
affected
Version
fbac09a3b8890003c0c55294c00709f3ae5501bb
Status
affected
Version
5b48f5711f1c630841ab78dcc061de902f0e37bf
Status
affected
Version
edb4baffb9483141a50fb7f7146cfe4a4c0c2db8
Status
affected
Version
5.10.130
Version <
5.10.265
Status
affected
Version
5.15.54
Version <
5.15.216
Status
affected
Version
4.19.252
Version <
4.20
Status
affected
Version
5.4.205
Version <
5.5
Status
affected
Version
5.18.11
Version <
5.19
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.19
Status
affected
Version
0
Version <
5.19
Status
unaffected
Version <=
5.10.*
Version
5.10.265
Status
unaffected
Version <=
5.15.*
Version
5.15.216
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/3cf4fd5316f449811d8baf1bc6978ef5a7b743a9
https://git.kernel.org/stable/c/4177762f70646ac48a2af382e45a795cbd295198
https://git.kernel.org/stable/c/6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f
https://git.kernel.org/stable/c/cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5
https://git.kernel.org/stable/c/ce2d4b121fb7545e1ed588e860c8e5fd5ad45224
https://git.kernel.org/stable/c/68973f9db76144825e4f35dfdc80fb8279eb2d57
https://git.kernel.org/stable/c/036a8c320ca11bc912e8027adcfad14b326f067e
https://git.kernel.org/stable/c/de5fce46637de05bef56ec08528127676eb6fc9b