๐Ÿ” CVE Alert

CVE-2026-64585

UNKNOWN 0.0

can: esd_usb: kill anchored URBs before freeing netdevs

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing netdevs esd_usb_disconnect() frees each CAN netdev with free_candev() inside its per-netdev loop and only calls unlink_all_urbs(dev) afterwards. The per-netdev private data (struct esd_usb_net_priv) is embedded in the net_device allocation returned by alloc_candev(), so once free_candev() has run, dev->nets[i] points to freed memory. unlink_all_urbs() then dereferences the freed dev->nets[i] to kill the per-netdev TX anchor (usb_kill_anchored_urbs(&priv->tx_submitted)), clear active_tx_jobs, and reset priv->tx_contexts[]. Reorder the teardown so the anchored URBs are killed before the netdevs are freed, matching other CAN/USB drivers in the same directory such as ems_usb, usb_8dev and mcba_usb, which unregister, then unlink, then free: unregister the netdevs first (which stops their TX queues), call unlink_all_urbs(dev) once, then free the netdevs. This issue was found by an in-house static analysis tool.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
96d8e90382dc336b5de401164597edfdc2e8d9f1 < aa1d005927db38af783c1a4a8a00a39e0229ab2d 96d8e90382dc336b5de401164597edfdc2e8d9f1 < a02e1d8f191324583599544d54e59e6a2b74bb0e 96d8e90382dc336b5de401164597edfdc2e8d9f1 < a3314f10369df70925140f59bbe069718f65a0b9 96d8e90382dc336b5de401164597edfdc2e8d9f1 < 765ba1c91823a296447528791b89a6504947fd5c 96d8e90382dc336b5de401164597edfdc2e8d9f1 < 5832c55b3c824ba2fe9c36ac3c411baddcce053e 96d8e90382dc336b5de401164597edfdc2e8d9f1 < c43122fef328a70045fe7621c06de6b2b8e19264
Linux / Linux
2.6.36

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/aa1d005927db38af783c1a4a8a00a39e0229ab2d git.kernel.org: https://git.kernel.org/stable/c/a02e1d8f191324583599544d54e59e6a2b74bb0e git.kernel.org: https://git.kernel.org/stable/c/a3314f10369df70925140f59bbe069718f65a0b9 git.kernel.org: https://git.kernel.org/stable/c/765ba1c91823a296447528791b89a6504947fd5c git.kernel.org: https://git.kernel.org/stable/c/5832c55b3c824ba2fe9c36ac3c411baddcce053e git.kernel.org: https://git.kernel.org/stable/c/c43122fef328a70045fe7621c06de6b2b8e19264