Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80658.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-80658
Upstream
Published
2026-03-25T11:16:25Z
Modified
2026-08-28T17:46:33.785567354Z
Summary
CVE-2026-23298 affecting package kernel for versions less than 6.6.130.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

can: ucan: Fix infinite loop from zero-length messages

If a broken ucan device gets a message with the message length field set to 0, then the driver will loop for forever in ucanreadbulk_callback(), hanging the system. If the length is 0, just skip the message and go on to the next one.

This has been fixed in the kvaserusb driver in the past in commit 0c73772cd2b8 ("can: kvaserusb: leaf: Fix potential infinite loop in command parsers"), so there must be some broken devices out there like this somewhere.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.130.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-80658.json"