CVE-2026-72115
Received Received - Intake

Race Condition in Linux Kernel CAN BCM Module

Vulnerability report for CVE-2026-72115, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-19

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDEV timeout/throttle ops An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces: bcm_rx_handler() can run concurrently for the same op on different CPUs, racing hrtimer_cancel()/ bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing spurious RX_TIMEOUT notifications and last_frames corruption. The same concurrency lets throttled multiplex frames from different interfaces clobber the single rx_ifindex/rx_stamp fields shared by the op. Add op->if_detected to track the first interface that delivers a matching frame while a timeout/throttle timer is configured, and reject frames from any other interface for that op. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME, independent of kt_ival1/kt_ival2, since those may briefly hold a stale value from an earlier non-RTR configuration. The claim is released in bcm_notify() on NETDEV_UNREGISTER and in bcm_rx_setup() when SETTIMER reconfigures the timer values. A (re-)claim is only possible on CAN devices in NETREG_REGISTERED dev->reg_state to cover the release in bcm_notify() where reg_state becomes NETREG_UNREGISTERING until synchronize_net().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-19
Generated
2026-09-04
AI Q&A
2026-08-15
EPSS Evaluated
2026-09-03
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Linux kernel's CAN BCM protocol implementation. It involves a race condition in handling ANYDEV rx operations with active timeout or throttle timers. When frames arrive from multiple interfaces, concurrent execution can corrupt shared fields, leading to incorrect timeout notifications and data corruption.

Detection Guidance

This vulnerability is specific to the Linux kernel's CAN BCM module and may not have direct detection commands. Monitor kernel logs for CAN-related errors or warnings using 'dmesg | grep -i can' or 'journalctl -k | grep -i can'. Check for spurious RX_TIMEOUT notifications or last_frames corruption in CAN device logs.

Impact Analysis

This vulnerability could cause CAN network communication issues, including spurious timeout errors and corrupted data frames. It may disrupt real-time CAN applications relying on BCM protocol for message handling and filtering.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it pertains to CAN bus operations in the Linux kernel. It involves race conditions in CAN protocol handling, not data privacy or security controls required by these regulations.

Mitigation Strategies

Update the Linux kernel to the latest patched version that includes the fix for CVE-2026-72115. If immediate patching is not possible, disable the CAN BCM module if not required by unloading the module with 'modprobe -r can_bcm' or blacklisting it in configuration files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72115. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart