CVE-2026-72115
can: bcm: track a single source interface for ANYDEV timeout/throttle ops
Description
In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDEV timeout/throttle ops An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces: bcm_rx_handler() can run concurrently for the same op on different CPUs, racing hrtimer_cancel()/ bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing spurious RX_TIMEOUT notifications and last_frames corruption. The same concurrency lets throttled multiplex frames from different interfaces clobber the single rx_ifindex/rx_stamp fields shared by the op. Add op->if_detected to track the first interface that delivers a matching frame while a timeout/throttle timer is configured, and reject frames from any other interface for that op. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME, independent of kt_ival1/kt_ival2, since those may briefly hold a stale value from an earlier non-RTR configuration. The claim is released in bcm_notify() on NETDEV_UNREGISTER and in bcm_rx_setup() when SETTIMER reconfigures the timer values. A (re-)claim is only possible on CAN devices in NETREG_REGISTERED dev->reg_state to cover the release in bcm_notify() where reg_state becomes NETREG_UNREGISTERING until synchronize_net().
INFO
Published Date :
Aug. 15, 2026, 6:21 a.m.
Last Modified :
Aug. 17, 2026, 6:18 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Update the Linux kernel to the latest stable version.
- Apply the specific patch addressing the bcm: track source interface issue.
- Rebuild and install the updated kernel.
- Reboot the system to load the new kernel.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-72115.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-72115 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-72115
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-72115 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-72115 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '18b45251e74e35668f0dd0c470549384ae191ecf', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '3ff8c24b421070a2db99a5cdb86edc9ff339418e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': 'eca8b44d51fc6ab61022258ec968e55e3073b79e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': 'b6317022b685a430a3ae420456716e3c0c02ef4b', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '2f5976f54a04e9f18b25283036ac3136be453b17', 'versionType': 'git'}], 'programFiles': ['net/can/bcm.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.25'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.25', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc4', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/can/bcm.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '18b45251e74e35668f0dd0c470549384ae191ecf', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '3ff8c24b421070a2db99a5cdb86edc9ff339418e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': 'eca8b44d51fc6ab61022258ec968e55e3073b79e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': 'b6317022b685a430a3ae420456716e3c0c02ef4b', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '2f5976f54a04e9f18b25283036ac3136be453b17', 'versionType': 'git'}], 'programFiles': ['net/can/bcm.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.25'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.25', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/can/bcm.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '18b45251e74e35668f0dd0c470549384ae191ecf', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '3ff8c24b421070a2db99a5cdb86edc9ff339418e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': 'eca8b44d51fc6ab61022258ec968e55e3073b79e', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': 'b6317022b685a430a3ae420456716e3c0c02ef4b', 'versionType': 'git'}, {'status': 'affected', 'version': 'ffd980f976e7fd666c2e61bf8ab35107efd11828', 'lessThan': '2f5976f54a04e9f18b25283036ac3136be453b17', 'versionType': 'git'}], 'programFiles': ['net/can/bcm.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2.6.25'}, {'status': 'unaffected', 'version': '0', 'lessThan': '2.6.25', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.6.148', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.101', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.42', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc4', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['net/can/bcm.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDEV timeout/throttle ops An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces: bcm_rx_handler() can run concurrently for the same op on different CPUs, racing hrtimer_cancel()/ bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing spurious RX_TIMEOUT notifications and last_frames corruption. The same concurrency lets throttled multiplex frames from different interfaces clobber the single rx_ifindex/rx_stamp fields shared by the op. Add op->if_detected to track the first interface that delivers a matching frame while a timeout/throttle timer is configured, and reject frames from any other interface for that op. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME, independent of kt_ival1/kt_ival2, since those may briefly hold a stale value from an earlier non-RTR configuration. The claim is released in bcm_notify() on NETDEV_UNREGISTER and in bcm_rx_setup() when SETTIMER reconfigures the timer values. A (re-)claim is only possible on CAN devices in NETREG_REGISTERED dev->reg_state to cover the release in bcm_notify() where reg_state becomes NETREG_UNREGISTERING until synchronize_net(). Added Reference https://git.kernel.org/stable/c/18b45251e74e35668f0dd0c470549384ae191ecf Added Reference https://git.kernel.org/stable/c/2f5976f54a04e9f18b25283036ac3136be453b17 Added Reference https://git.kernel.org/stable/c/3ff8c24b421070a2db99a5cdb86edc9ff339418e Added Reference https://git.kernel.org/stable/c/b6317022b685a430a3ae420456716e3c0c02ef4b Added Reference https://git.kernel.org/stable/c/eca8b44d51fc6ab61022258ec968e55e3073b79e