« Volver al listado

CVE-2026-72116

Estado: RecibidaAlta (7.1)—

In the Linux kernel, the following vulnerability has been resolved:

can: bcm: fix stale rx/tx ops after device removal

RX: an RX_SETUP update(!) for an existing op skipped can_rx_register() unconditionally, even when a concurrent NETDEV_UNREGISTER had already torn down its registration (op->rx_reg_dev == NULL). This silently did not re-enable frame delivery for that updated filter. bcm_rx_setup() now re-registers in that case, while leaving rx_ops with ifindex = 0 (all CAN devices) which never carry a tracked rx_reg_dev registered as-is.

TX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving tx_ops with an active cyclic transmission re-arming its hrtimer indefinitely to execute bcm_tx_timeout_handler().

Leer descripción completaMostrar menos

Cancelling the hrtimer prevents the runaway timer and any injection into a later reused ifindex, since nothing else calls bcm_can_tx() for the op until an explicit TX_SETUP update re-arms it.

Unlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops, the ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup() always rejects ifindex 0, so clearing it would strand the op: neither a later TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could ever find it again, since both require an exact ifindex match.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local con PR:L sin interacción (AV:L/PR:L/UI:N). La vulnerabilidad permite que un proceso local manipule temporizadores y transmisión CAN tras desregistro de dispositivo, causando ejecución arbitraria y corrupción de datos en operaciones de red.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72116",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
              "lessThan": "d30a36066ed3abefb72ae18901f71841ba18b350",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
              "lessThan": "ca829677ffa2de5d79e06366e19ac1e4f5cc78dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
              "lessThan": "9517d8fb0b191398d35b9b7f8c719c1cc7761cb1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
              "lessThan": "60d8a7942f4ed2d975207aaeba1adb576707e53d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
              "lessThan": "f749e4564952d60e96930c09f2be99955d07c22e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
              "lessThan": "6be3e1fedf03eab36a2c09d755d1171287b2014b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
              "lessThan": "b31d0933509c5a35c0be5736a2ce8df0d1bf112c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ffd980f976e7fd666c2e61bf8ab35107efd11828",
              "lessThan": "3b762c0d950383ab7a002686c9136b9aa55d2d70",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/can/bcm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.25"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.25",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/can/bcm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:26.020",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3b762c0d950383ab7a002686c9136b9aa55d2d70",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/60d8a7942f4ed2d975207aaeba1adb576707e53d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6be3e1fedf03eab36a2c09d755d1171287b2014b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9517d8fb0b191398d35b9b7f8c719c1cc7761cb1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b31d0933509c5a35c0be5736a2ce8df0d1bf112c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ca829677ffa2de5d79e06366e19ac1e4f5cc78dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d30a36066ed3abefb72ae18901f71841ba18b350",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f749e4564952d60e96930c09f2be99955d07c22e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: fix stale rx/tx ops after device removal\n\nRX: an RX_SETUP update(!) for an existing op skipped can_rx_register()\nunconditionally, even when a concurrent NETDEV_UNREGISTER had already\ntorn down its registration (op->rx_reg_dev == NULL). This silently\ndid not re-enable frame delivery for that updated filter. bcm_rx_setup()\nnow re-registers in that case, while leaving rx_ops with ifindex = 0\n(all CAN devices) which never carry a tracked rx_reg_dev registered as-is.\n\nTX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving\ntx_ops with an active cyclic transmission re-arming its hrtimer\nindefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer\nprevents the runaway timer and any injection into a later reused ifindex,\nsince nothing else calls bcm_can_tx() for the op until an explicit\nTX_SETUP update re-arms it.\n\nUnlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops,\nthe ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup()\nalways rejects ifindex 0, so clearing it would strand the op: neither a\nlater TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could\never find it again, since both require an exact ifindex match."
    }
  ],
  "lastModified": "2026-08-19T17:20:57.960",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}