๐Ÿ” CVE Alert

CVE-2026-23061

UNKNOWN 0.0

can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak Fix similar memory leak as in commit 7352e1d5932a ("can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak"). In kvaser_usb_set_{,data_}bittiming() -> kvaser_usb_setup_rx_urbs(), the URBs for USB-in transfers are allocated, added to the dev->rx_submitted anchor and submitted. In the complete callback kvaser_usb_read_bulk_callback(), the URBs are processed and resubmitted. In kvaser_usb_remove_interfaces() the URBs are freed by calling usb_kill_anchored_urbs(&dev->rx_submitted). However, this does not take into account that the USB framework unanchors the URB before the complete function is called. This means that once an in-URB has been completed, it is no longer anchored and is ultimately not released in usb_kill_anchored_urbs(). Fix the memory leak by anchoring the URB in the kvaser_usb_read_bulk_callback() to the dev->rx_submitted anchor.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Feb 4, 2026
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
080f40a6fa28dab299da7a652e444b1e2d9231e7 < d9d824582f2ec76459ffab449e9b05c7bc49645c 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 40a3334ffda479c63e416e61ff086485e24401f7 080f40a6fa28dab299da7a652e444b1e2d9231e7 < c1b39fa24c140bc616f51fef4175c1743e2bb132 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 7c308f7530bffafa994e0aa8dc651a312f4b9ff4 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 94a7fc42e21c7d9d1c49778cd1db52de5df52a01 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 3b1a593eab941c3f32417896cc7df564191f2482 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 248e8e1a125fa875158df521b30f2cc7e27eeeaa
Linux / Linux
3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d9d824582f2ec76459ffab449e9b05c7bc49645c git.kernel.org: https://git.kernel.org/stable/c/40a3334ffda479c63e416e61ff086485e24401f7 git.kernel.org: https://git.kernel.org/stable/c/c1b39fa24c140bc616f51fef4175c1743e2bb132 git.kernel.org: https://git.kernel.org/stable/c/7c308f7530bffafa994e0aa8dc651a312f4b9ff4 git.kernel.org: https://git.kernel.org/stable/c/94a7fc42e21c7d9d1c49778cd1db52de5df52a01 git.kernel.org: https://git.kernel.org/stable/c/3b1a593eab941c3f32417896cc7df564191f2482 git.kernel.org: https://git.kernel.org/stable/c/248e8e1a125fa875158df521b30f2cc7e27eeeaa