๐Ÿ” CVE Alert

CVE-2026-23108

UNKNOWN 0.0

can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak Fix similar memory leak as in commit 7352e1d5932a ("can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak"). In usb_8dev_open() -> usb_8dev_start(), the URBs for USB-in transfers are allocated, added to the priv->rx_submitted anchor and submitted. In the complete callback usb_8dev_read_bulk_callback(), the URBs are processed and resubmitted. In usb_8dev_close() -> unlink_all_urbs() the URBs are freed by calling usb_kill_anchored_urbs(&priv->rx_submitted). However, this does not take into account that the USB framework unanchors the URB before the complete function is called. This means that once an in-URB has been completed, it is no longer anchored and is ultimately not released in usb_kill_anchored_urbs(). Fix the memory leak by anchoring the URB in the usb_8dev_read_bulk_callback() to the priv->rx_submitted anchor.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Feb 4, 2026
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0024d8ad1639e32d717445c69ca813fd19c2a91c < feb8243eaea7efd5279b19667d7189fd8654c87a 0024d8ad1639e32d717445c69ca813fd19c2a91c < ef6e608e5ee71eca0cd3475c737e684cef24f240 0024d8ad1639e32d717445c69ca813fd19c2a91c < 60719661b4cbd7ffbed1a0e0fa3bbc82d8bd2be9 0024d8ad1639e32d717445c69ca813fd19c2a91c < 59ff56992bba28051ad67cd8cc7b0edfe7280796 0024d8ad1639e32d717445c69ca813fd19c2a91c < ea4a98e924164586066b39f29bfcc7cc9da108cd 0024d8ad1639e32d717445c69ca813fd19c2a91c < 07e9373739c6388af9d99797cdb2e79dbbcbe92b 0024d8ad1639e32d717445c69ca813fd19c2a91c < f7a980b3b8f80fe367f679da376cf76e800f9480
Linux / Linux
3.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/feb8243eaea7efd5279b19667d7189fd8654c87a git.kernel.org: https://git.kernel.org/stable/c/ef6e608e5ee71eca0cd3475c737e684cef24f240 git.kernel.org: https://git.kernel.org/stable/c/60719661b4cbd7ffbed1a0e0fa3bbc82d8bd2be9 git.kernel.org: https://git.kernel.org/stable/c/59ff56992bba28051ad67cd8cc7b0edfe7280796 git.kernel.org: https://git.kernel.org/stable/c/ea4a98e924164586066b39f29bfcc7cc9da108cd git.kernel.org: https://git.kernel.org/stable/c/07e9373739c6388af9d99797cdb2e79dbbcbe92b git.kernel.org: https://git.kernel.org/stable/c/f7a980b3b8f80fe367f679da376cf76e800f9480