๐Ÿ” CVE Alert

CVE-2026-72115

UNKNOWN 0.0

can: bcm: track a single source interface for ANYDEV timeout/throttle ops

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDEV timeout/throttle ops An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces: bcm_rx_handler() can run concurrently for the same op on different CPUs, racing hrtimer_cancel()/ bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing spurious RX_TIMEOUT notifications and last_frames corruption. The same concurrency lets throttled multiplex frames from different interfaces clobber the single rx_ifindex/rx_stamp fields shared by the op. Add op->if_detected to track the first interface that delivers a matching frame while a timeout/throttle timer is configured, and reject frames from any other interface for that op. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME, independent of kt_ival1/kt_ival2, since those may briefly hold a stale value from an earlier non-RTR configuration. The claim is released in bcm_notify() on NETDEV_UNREGISTER and in bcm_rx_setup() when SETTIMER reconfigures the timer values. A (re-)claim is only possible on CAN devices in NETREG_REGISTERED dev->reg_state to cover the release in bcm_notify() where reg_state becomes NETREG_UNREGISTERING until synchronize_net().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ffd980f976e7fd666c2e61bf8ab35107efd11828 < 18b45251e74e35668f0dd0c470549384ae191ecf ffd980f976e7fd666c2e61bf8ab35107efd11828 < 3ff8c24b421070a2db99a5cdb86edc9ff339418e ffd980f976e7fd666c2e61bf8ab35107efd11828 < eca8b44d51fc6ab61022258ec968e55e3073b79e ffd980f976e7fd666c2e61bf8ab35107efd11828 < b6317022b685a430a3ae420456716e3c0c02ef4b ffd980f976e7fd666c2e61bf8ab35107efd11828 < 2f5976f54a04e9f18b25283036ac3136be453b17
Linux / Linux
2.6.25

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/18b45251e74e35668f0dd0c470549384ae191ecf git.kernel.org: https://git.kernel.org/stable/c/3ff8c24b421070a2db99a5cdb86edc9ff339418e git.kernel.org: https://git.kernel.org/stable/c/eca8b44d51fc6ab61022258ec968e55e3073b79e git.kernel.org: https://git.kernel.org/stable/c/b6317022b685a430a3ae420456716e3c0c02ef4b git.kernel.org: https://git.kernel.org/stable/c/2f5976f54a04e9f18b25283036ac3136be453b17