CVE-2026-72113
Received Received - Intake

CAN Refcount Leak in Linux Kernel

Vulnerability report for CVE-2026-72113, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-15

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing device refcount for CAN filter removal sashiko-bot remarked a problem with a concurrent device unregistration in isotp.c which also is present in the bcm.c code. A former fix for raw.c commit c275a176e4b6 ("can: raw: add missing refcount for memory leak fix") introduced a netdevice_tracker which solves the issue for bcm.c too. bcm_release(), bcm_delete_rx_op() and bcm_notifier() relied on dev_get_by_index(ifindex) to re-find the device for an rx_op before unregistering its filter. If a concurrent NETDEV_UNREGISTER has already unlisted the device from the ifindex table, that lookup fails and can_rx_unregister() is silently skipped, leaving a stale CAN filter pointing at the soon-to-be-freed bcm_op/socket. Hold a netdev_hold()/netdev_put() tracked reference on op->rx_reg_dev from the moment the rx filter is registered in bcm_rx_setup() until it is unregistered in bcm_rx_unreg(), and use that reference directly in bcm_release() and bcm_delete_rx_op() instead of re-looking the device up by ifindex.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-15
Generated
2026-08-15
AI Q&A
2026-08-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a missing device reference count in the CAN BCM protocol's filter removal process. When a CAN filter is unregistered, the code fails to properly hold a reference to the network device, which can lead to a use-after-free scenario if the device is concurrently unregistered. This allows stale CAN filters to remain pointing to freed memory.

Detection Guidance

This vulnerability involves stale CAN filters due to improper device reference handling. Detection requires checking for unregistered CAN filters or devices. Use commands like 'ip -details link show' to inspect CAN interfaces and 'dmesg | grep can' to check for kernel messages related to CAN filter issues.

Impact Analysis

This vulnerability could lead to system crashes, privilege escalation, or denial of service if exploited. Attackers might trigger the race condition to cause memory corruption by manipulating network device unregistration while CAN filters are being removed.

Mitigation Strategies

Apply the Linux kernel patch that resolves this issue. Update to a kernel version containing the fix for bcm.c device refcount handling. Restart affected systems to ensure the patched kernel is active.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72113. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart