CVE-2026-72115
CVE CVE-2026-72115EUVD EUVD-2026-59073Veröffentlicht 2026-08-15T05:52:55.000ZZuletzt geändert 2026-08-19T16:36:03.000ZCVSS 8.1
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDEV timeout/throttle ops An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces: bcm_rx_handler() can run concurrently for the same op on different CPUs, racing hrtimer_cancel()/ bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing spurious RX_TIMEOUT notifications and last_frames corruption. The same concurrency lets throttled multiplex frames from different interfaces clobber the single rx_ifindex/rx_stamp fields shared by the op. Add op->if_detected to track the first interface that delivers a matching frame while a timeout/throttle timer is configured, and reject frames from any other interface for that op. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME, independent of kt_ival1/kt_ival2, since those may briefly hold a stale value from an earlier non-RTR configuration. The claim is released in bcm_notify() on NETDEV_UNREGISTER and in bcm_rx_setup() when SETTIMER reconfigures the timer values. A (re-)claim is only possible on CAN devices in NETREG_REGISTERED dev->reg_state to cover the release in bcm_notify() where reg_state becomes NETREG_UNREGISTERING until synchronize_net().
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux ffd980f976e7fd666c2e61bf8ab35107efd11828 <57cf104da4cf450ae9c16801a3164604b801d2cc; patch: 0; ffd980f976e7fd666c2e61bf8ab35107efd11828 <eca8b44d51fc6ab61022258ec968e55e3073b79e; patch: 6.18.42; ffd980f976e7fd666c2e61bf8ab35107efd11828 <03dfe347c398fa41a7e30e8dc538f12568c183e6; patch: 7.2; patch: 5.15.216; ffd980f976e7fd666c2e61bf8ab35107efd11828 <2f5976f54a04e9f18b25283036ac3136be453b17; patch: 6.12.101; patch: 7.1.5; patch: 6.6.148; ffd980f976e7fd666c2e61bf8ab35107efd11828 <f147f48837cb1426521f5b3c3b3134c71128a25d; 2.6.25; ffd980f976e7fd666c2e61bf8ab35107efd11828 <18b45251e74e35668f0dd0c470549384ae191ecf; ffd980f976e7fd666c2e61bf8ab35107efd11828 <3ff8c24b421070a2db99a5cdb86edc9ff339418e; patch: 5.10.265; ffd980f976e7fd666c2e61bf8ab35107efd11828 <b6317022b685a430a3ae420456716e3c0c02ef4b; patch: 6.1.183
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.