« Volver al listado

CVE-2026-23155

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

can: gs_usb: gs_usb_receive_bulk_callback(): fix error message

Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error") a failing resubmit URB will print an info message.

In the case of a short read where netdev has not yet been assigned, initialize as NULL to avoid dereferencing an undefined value. Also report the error value of the failed resubmit.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-23155",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "da01de754e455e2598a7f1ce4ff2078c4f0ecde1",
              "lessThan": "7a431df418ee6b79841e0b4c7c265a791e3d0a75",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "aa8a8866c533a150be4763bcb27993603bd5426c",
              "lessThan": "aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ce4352057fc5a986c76ece90801b9755e7c6e56c",
              "lessThan": "923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c610b550ccc0438d456dfe1df9f4f36254ccaae3",
              "lessThan": "8986cdf52f86208df9c7887fee23365b5d37da26",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c3edc14da81a8d8398682f6e4ab819f09f37c0b7",
              "lessThan": "713ba826ae114ab339c9a1b31e209bebdadb0ac9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "79a6d1bfe1148bc921b8d7f3371a7fbce44e30f7",
              "lessThan": "494fc029f662c331e06b7c2031deff3c64200eed",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/can/usb/gs_usb.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6.122",
              "lessThan": "6.6.123",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.68",
              "lessThan": "6.12.69",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.8",
              "lessThan": "6.18.9",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/net/can/usb/gs_usb.c"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-02-14T16:15:55.653",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/494fc029f662c331e06b7c2031deff3c64200eed",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/713ba826ae114ab339c9a1b31e209bebdadb0ac9",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7a431df418ee6b79841e0b4c7c265a791e3d0a75",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8986cdf52f86208df9c7887fee23365b5d37da26",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-476"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: gs_usb: gs_usb_receive_bulk_callback(): fix error message\n\nSinc commit 79a6d1bfe114 (\"can: gs_usb: gs_usb_receive_bulk_callback():\nunanchor URL on usb_submit_urb() error\") a failing resubmit URB will print\nan info message.\n\nIn the case of a short read where netdev has not yet been assigned,\ninitialize as NULL to avoid dereferencing an undefined value. Also report\nthe error value of the failed resubmit."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\ncan: gs_usb: gs_usb_receive_bulk_callback(): corregir mensaje de error\n\nDesde el commit 79a6d1bfe114 ('can: gs_usb: gs_usb_receive_bulk_callback(): desanclar URL en error de usb_submit_urb()'), un URB de reenvío fallido imprimirá un mensaje de información.\n\nEn el caso de una lectura corta donde netdev aún no ha sido asignado, inicializar como NULL para evitar desreferenciar un valor indefinido. También informar el valor de error del reenvío fallido."
    }
  ],
  "lastModified": "2026-06-17T10:21:00.107",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.6.122:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86B92AB2-1FB7-4D1D-8D0C-B6FE241FB4B5"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.12.68:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B0724BD-589D-42C4-9456-646D8CBCF8A4"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.18.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1356361D-D06B-4A76-8D92-0B20D30F3D59"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F5DC0CA6-F0AF-4DDF-A882-3DADB9A886A7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}