CVE-2026-72114

Source
https://cve.org/CVERecord?id=CVE-2026-72114
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72114.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72114
Downstream
Published
2026-08-15T05:52:54.750Z
Modified
2026-08-20T03:55:05.164487072Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
can: bcm: validate frame length in bcm_rx_setup() for RTR replies
Details

In the Linux kernel, the following vulnerability has been resolved:

can: bcm: validate frame length in bcmrxsetup() for RTR replies

bcmtxsetup() validates cf->len against the CAN/CAN FD DLC limits before installing frames for TXSETUP, but bcmrxsetup() never did the same for the RTR-reply frame configured via RXSETUP with RXRTRFRAME.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72114.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ffd980f976e7fd666c2e61bf8ab35107efd11828
Fixed
cc1f9569f1c1adf74fa69d6f716a31b58a2fc6ce
Fixed
204f2b232717bc470ddb9e1da1d27dd9c6ef0caa
Fixed
e061624c0a86c3c26a2bf017e432fbc93ad68f3a
Fixed
7d966cdee006911d3957e1a4e72cb93c39cd8c1e
Fixed
1b475c0c72f44622a320a4386ce9e76f85e69bc7
Fixed
deb6a697cce3f021e731df543597f37a5e54caab
Fixed
59bfddea64159594feb62ef11b7d7a33c8ee3783
Fixed
62ec41f364648be79d54d94d0d240ee326948afd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72114.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.25
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72114.json"