« Volver al listado

CVE-2026-23037

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

can: etas_es58x: allow partial RX URB allocation to succeed

When es58x_alloc_rx_urbs() fails to allocate the requested number of URBs but succeeds in allocating some, it returns an error code. This causes es58x_open() to return early, skipping the cleanup label 'free_urbs', which leads to the anchored URBs being leaked.

As pointed out by maintainer Vincent Mailhol, the driver is designed to handle partial URB allocation gracefully. Therefore, partial allocation should not be treated as a fatal error.

Modify es58x_alloc_rx_urbs() to return 0 if at least one URB has been allocated, restoring the intended behavior and preventing the leak in es58x_open().

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-23037",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8537257874e949a59c834cecfd5a063e11b64b0b",
              "lessThan": "97250eb05e4b6afe787290e8fd97d0675116c61b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8537257874e949a59c834cecfd5a063e11b64b0b",
              "lessThan": "aec888f44853584b5a7cd01249806030cf94a73d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8537257874e949a59c834cecfd5a063e11b64b0b",
              "lessThan": "611e839d2d552416b498ed5593e10670f61fcd4d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8537257874e949a59c834cecfd5a063e11b64b0b",
              "lessThan": "ba45e3d6b02c97dbb4578fbae7027fd66f3caa10",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8537257874e949a59c834cecfd5a063e11b64b0b",
              "lessThan": "6c5124a60989051799037834f0a1a4b428718157",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8537257874e949a59c834cecfd5a063e11b64b0b",
              "lessThan": "b1979778e98569c1e78c2c7f16bb24d76541ab00",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/can/usb/etas_es58x/es58x_core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.199",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.162",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.122",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.67",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.7",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/can/usb/etas_es58x/es58x_core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "RUGGEDCOM RST2428P",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V4.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-01-31T12:16:07.010",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/611e839d2d552416b498ed5593e10670f61fcd4d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6c5124a60989051799037834f0a1a4b428718157",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/97250eb05e4b6afe787290e8fd97d0675116c61b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aec888f44853584b5a7cd01249806030cf94a73d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b1979778e98569c1e78c2c7f16bb24d76541ab00",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba45e3d6b02c97dbb4578fbae7027fd66f3caa10",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: etas_es58x: allow partial RX URB allocation to succeed\n\nWhen es58x_alloc_rx_urbs() fails to allocate the requested number of\nURBs but succeeds in allocating some, it returns an error code.\nThis causes es58x_open() to return early, skipping the cleanup label\n'free_urbs', which leads to the anchored URBs being leaked.\n\nAs pointed out by maintainer Vincent Mailhol, the driver is designed\nto handle partial URB allocation gracefully. Therefore, partial\nallocation should not be treated as a fatal error.\n\nModify es58x_alloc_rx_urbs() to return 0 if at least one URB has been\nallocated, restoring the intended behavior and preventing the leak\nin es58x_open()."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\ncan: etas_es58x: permitir que la asignación parcial de URB RX tenga éxito\n\nCuando es58x_alloc_rx_urbs() falla al asignar el número solicitado de URBs pero logra asignar algunos, devuelve un código de error. Esto hace que es58x_open() retorne prematuramente, saltándose la etiqueta de limpieza 'free_urbs', lo que lleva a la fuga de los URBs anclados.\n\nComo señaló el mantenedor Vincent Mailhol, el controlador está diseñado para manejar la asignación parcial de URB de manera elegante. Por lo tanto, la asignación parcial no debe ser tratada como un error fatal.\n\nModificar es58x_alloc_rx_urbs() para que devuelva 0 si al menos un URB ha sido asignado, restaurando el comportamiento previsto y previniendo la fuga en es58x_open()."
    }
  ],
  "lastModified": "2026-06-17T10:20:45.250",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}