CVE-2026-23082
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error
In commit 7352e1d5932a ("can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak"), the URB was re-anchored before usb_submit_urb() in gs_usb_receive_bulk_callback() to prevent a leak of this URB during cleanup.
However, this patch did not take into account that usb_submit_urb() could fail. The URB remains anchored and usb_kill_anchored_urbs(&parent->rx_submitted) in gs_can_close() loops infinitely since the anchor list never becomes empty.
Read full descriptionShow less
To fix the bug, unanchor the URB when an usb_submit_urb() error occurs, also print an info message.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Base score: 5.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.14%
- Percentile among all scored CVEs: 3
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-835
References
- https://git.kernel.org/stable/c/79a6d1bfe1148bc921b8d7f3371a7fbce44e30f7
- https://git.kernel.org/stable/c/aa8a8866c533a150be4763bcb27993603bd5426c
- https://git.kernel.org/stable/c/c3edc14da81a8d8398682f6e4ab819f09f37c0b7
- https://git.kernel.org/stable/c/c610b550ccc0438d456dfe1df9f4f36254ccaae3
- https://git.kernel.org/stable/c/ce4352057fc5a986c76ece90801b9755e7c6e56c
- https://git.kernel.org/stable/c/da01de754e455e2598a7f1ce4ff2078c4f0ecde1
Raw JSON (NVD)
Show
{
"id": "CVE-2026-23082",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "9c151898cc259a7784be60ba38664f42ede39b31",
"lessThan": "da01de754e455e2598a7f1ce4ff2078c4f0ecde1",
"versionType": "git"
},
{
"status": "affected",
"version": "ec5ccc2af9e5b045671f3f604b57512feda8bcc5",
"lessThan": "aa8a8866c533a150be4763bcb27993603bd5426c",
"versionType": "git"
},
{
"status": "affected",
"version": "f905bcfa971edb89e398c98957838d8c6381c0c7",
"lessThan": "ce4352057fc5a986c76ece90801b9755e7c6e56c",
"versionType": "git"
},
{
"status": "affected",
"version": "08624b7206ddb9148eeffc2384ebda2c47b6d1e9",
"lessThan": "c610b550ccc0438d456dfe1df9f4f36254ccaae3",
"versionType": "git"
},
{
"status": "affected",
"version": "9f669a38ca70839229b7ba0f851820850a2fe1f7",
"lessThan": "c3edc14da81a8d8398682f6e4ab819f09f37c0b7",
"versionType": "git"
},
{
"status": "affected",
"version": "7352e1d5932a0e777e39fa4b619801191f57e603",
"lessThan": "79a6d1bfe1148bc921b8d7f3371a7fbce44e30f7",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/can/usb/gs_usb.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12.67",
"lessThan": "6.12.68",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.18.7",
"lessThan": "6.18.8",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/can/usb/gs_usb.c"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-02-04T17:16:19.060",
"references": [
{
"url": "https://git.kernel.org/stable/c/79a6d1bfe1148bc921b8d7f3371a7fbce44e30f7",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/aa8a8866c533a150be4763bcb27993603bd5426c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c3edc14da81a8d8398682f6e4ab819f09f37c0b7",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c610b550ccc0438d456dfe1df9f4f36254ccaae3",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ce4352057fc5a986c76ece90801b9755e7c6e56c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/da01de754e455e2598a7f1ce4ff2078c4f0ecde1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-835"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error\n\nIn commit 7352e1d5932a (\"can: gs_usb: gs_usb_receive_bulk_callback(): fix\nURB memory leak\"), the URB was re-anchored before usb_submit_urb() in\ngs_usb_receive_bulk_callback() to prevent a leak of this URB during\ncleanup.\n\nHowever, this patch did not take into account that usb_submit_urb() could\nfail. The URB remains anchored and\nusb_kill_anchored_urbs(&parent->rx_submitted) in gs_can_close() loops\ninfinitely since the anchor list never becomes empty.\n\nTo fix the bug, unanchor the URB when an usb_submit_urb() error occurs,\nalso print an info message."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\ncan: gs_usb: gs_usb_receive_bulk_callback(): desanclar URL en error de usb_submit_urb()\n\nEn el commit 7352e1d5932a (\"can: gs_usb: gs_usb_receive_bulk_callback(): corregir fuga de memoria de URB\"), el URB fue re-anclado antes de usb_submit_urb() en gs_usb_receive_bulk_callback() para prevenir una fuga de este URB durante la limpieza.\n\nSin embargo, este parche no tuvo en cuenta que usb_submit_urb() podría fallar. El URB permanece anclado y usb_kill_anchored_urbs(&parent->rx_submitted) en gs_can_close() entra en un bucle infinito ya que la lista de anclajes nunca queda vacía.\n\nPara corregir el error, desanclar el URB cuando ocurre un error de usb_submit_urb(), también imprimir un mensaje de información."
}
],
"lastModified": "2026-06-17T10:20:50.033",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.12.67:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59F27AC7-EC6E-439C-A4DE-3E0179CDFE1D"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.18.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "20B6C380-0FF3-4ECC-AA45-F055A5ECBFA1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EF854A1-ABB1-4E93-BE9A-44569EC76C0D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}