CVE-2026-23155
Estado: ModificadaMedia (5.5)—
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error") a failing resubmit URB will print an info message.
In the case of a short read where netdev has not yet been assigned, initialize as NULL to avoid dereferencing an undefined value. Also report the error value of the failed resubmit.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.12%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-476
Referencias
- https://git.kernel.org/stable/c/494fc029f662c331e06b7c2031deff3c64200eed
- https://git.kernel.org/stable/c/713ba826ae114ab339c9a1b31e209bebdadb0ac9
- https://git.kernel.org/stable/c/7a431df418ee6b79841e0b4c7c265a791e3d0a75
- https://git.kernel.org/stable/c/8986cdf52f86208df9c7887fee23365b5d37da26
- https://git.kernel.org/stable/c/923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6
- https://git.kernel.org/stable/c/aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23155",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "da01de754e455e2598a7f1ce4ff2078c4f0ecde1",
"lessThan": "7a431df418ee6b79841e0b4c7c265a791e3d0a75",
"versionType": "git"
},
{
"status": "affected",
"version": "aa8a8866c533a150be4763bcb27993603bd5426c",
"lessThan": "aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5",
"versionType": "git"
},
{
"status": "affected",
"version": "ce4352057fc5a986c76ece90801b9755e7c6e56c",
"lessThan": "923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6",
"versionType": "git"
},
{
"status": "affected",
"version": "c610b550ccc0438d456dfe1df9f4f36254ccaae3",
"lessThan": "8986cdf52f86208df9c7887fee23365b5d37da26",
"versionType": "git"
},
{
"status": "affected",
"version": "c3edc14da81a8d8398682f6e4ab819f09f37c0b7",
"lessThan": "713ba826ae114ab339c9a1b31e209bebdadb0ac9",
"versionType": "git"
},
{
"status": "affected",
"version": "79a6d1bfe1148bc921b8d7f3371a7fbce44e30f7",
"lessThan": "494fc029f662c331e06b7c2031deff3c64200eed",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/can/usb/gs_usb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.6.122",
"lessThan": "6.6.123",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.68",
"lessThan": "6.12.69",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.18.8",
"lessThan": "6.18.9",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/can/usb/gs_usb.c"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-02-14T16:15:55.653",
"references": [
{
"url": "https://git.kernel.org/stable/c/494fc029f662c331e06b7c2031deff3c64200eed",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/713ba826ae114ab339c9a1b31e209bebdadb0ac9",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7a431df418ee6b79841e0b4c7c265a791e3d0a75",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8986cdf52f86208df9c7887fee23365b5d37da26",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-476"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: gs_usb: gs_usb_receive_bulk_callback(): fix error message\n\nSinc commit 79a6d1bfe114 (\"can: gs_usb: gs_usb_receive_bulk_callback():\nunanchor URL on usb_submit_urb() error\") a failing resubmit URB will print\nan info message.\n\nIn the case of a short read where netdev has not yet been assigned,\ninitialize as NULL to avoid dereferencing an undefined value. Also report\nthe error value of the failed resubmit."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\ncan: gs_usb: gs_usb_receive_bulk_callback(): corregir mensaje de error\n\nDesde el commit 79a6d1bfe114 ('can: gs_usb: gs_usb_receive_bulk_callback(): desanclar URL en error de usb_submit_urb()'), un URB de reenvío fallido imprimirá un mensaje de información.\n\nEn el caso de una lectura corta donde netdev aún no ha sido asignado, inicializar como NULL para evitar desreferenciar un valor indefinido. También informar el valor de error del reenvío fallido."
}
],
"lastModified": "2026-06-17T10:21:00.107",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.6.122:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86B92AB2-1FB7-4D1D-8D0C-B6FE241FB4B5"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.12.68:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B0724BD-589D-42C4-9456-646D8CBCF8A4"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1356361D-D06B-4A76-8D92-0B20D30F3D59"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5DC0CA6-F0AF-4DDF-A882-3DADB9A886A7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}