CVE-2026-72115

Source
https://cve.org/CVERecord?id=CVE-2026-72115
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72115.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72115
Downstream
Published
2026-08-15T05:52:55.524Z
Modified
2026-08-18T03:56:20.602671883Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
can: bcm: track a single source interface for ANYDEV timeout/throttle ops
Details

In the Linux kernel, the following vulnerability has been resolved:

can: bcm: track a single source interface for ANYDEV timeout/throttle ops

An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces: bcmrxhandler() can run concurrently for the same op on different CPUs, racing hrtimercancel()/ bcmrxstarttimer() against bcmrxtimeouthandler() and causing spurious RXTIMEOUT notifications and lastframes corruption. The same concurrency lets throttled multiplex frames from different interfaces clobber the single rxifindex/rxstamp fields shared by the op.

Add op->ifdetected to track the first interface that delivers a matching frame while a timeout/throttle timer is configured, and reject frames from any other interface for that op. The claim is decided in bcmrxhandler() before hrtimercancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog. RTR-mode ops are excluded via RXRTRFRAME, independent of ktival1/ktival2, since those may briefly hold a stale value from an earlier non-RTR configuration.

The claim is released in bcmnotify() on NETDEVUNREGISTER and in bcmrxsetup() when SETTIMER reconfigures the timer values.

A (re-)claim is only possible on CAN devices in NETREGREGISTERED dev->regstate to cover the release in bcmnotify() where regstate becomes NETREGUNREGISTERING until synchronizenet().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72115.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ffd980f976e7fd666c2e61bf8ab35107efd11828
Fixed
18b45251e74e35668f0dd0c470549384ae191ecf
Fixed
3ff8c24b421070a2db99a5cdb86edc9ff339418e
Fixed
eca8b44d51fc6ab61022258ec968e55e3073b79e
Fixed
b6317022b685a430a3ae420456716e3c0c02ef4b
Fixed
2f5976f54a04e9f18b25283036ac3136be453b17

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72115.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.25
Fixed
6.6.148
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.101
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72115.json"