Answer in brief
CVE-2026-68387 records a Unknown severity vulnerability in can: raw: add locking for raw flags bitfield. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=890e5198a6e5b238627c245fafea1a92670a86cd <00ba4bf8798242253fefc1fa6a78db1d445fd024 || >=890e5198a6e5b238627c245fafea1a92670a86cd <57791aab1129c9405f84bb0882de58967d8b44cd || >=890e5198a6e5b238627c245fafea1a92670a86cd <1e5185c090589f4146d728ab36417d8a5419f127 | 00ba4bf8798242253fefc1fa6a78db1d445fd024, 57791aab1129c9405f84bb0882de58967d8b44cd, 1e5185c090589f4146d728ab36417d8a5419f127 |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: can: raw: add locking for raw flags bitfield With commit 890e5198a6e5 ("can: raw: use bitfields to store flags in struct raw_sock") the formerly separate integer values have been integrated into a single bitfield. This led to a read-modify-write operation when changing a flag in raw_setsockopt() which now needs a locking to prevent concurrent access. Instead of adding a lock/unlock hell in each of the flag manipulations this patch introduces a wrapper for a new raw_setsockopt_locked() function analogue to the isotp_setsockopt[_locked]() approach in net/can/isotp.c [mkl: use Closes tag instead of Link]
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68387 records a Unknown severity vulnerability in can: raw: add locking for raw flags bitfield. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=890e5198a6e5b238627c245fafea1a92670a86cd <00ba4bf8798242253fefc1fa6a78db1d445fd024 || >=890e5198a6e5b238627c245fafea1a92670a86cd <57791aab1129c9405f84bb0882de58967d8b44cd || >=890e5198a6e5b238627c245fafea1a92670a86cd <1e5185c090589f4146d728ab36417d8a5419f127 | 00ba4bf8798242253fefc1fa6a78db1d445fd024, 57791aab1129c9405f84bb0882de58967d8b44cd, 1e5185c090589f4146d728ab36417d8a5419f127 |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: can: raw: add locking for raw flags bitfield With commit 890e5198a6e5 ("can: raw: use bitfields to store flags in struct raw_sock") the formerly separate integer values have been integrated into a single bitfield. This led to a read-modify-write operation when changing a flag in raw_setsockopt() which now needs a locking to prevent concurrent access. Instead of adding a lock/unlock hell in each of the flag manipulations this patch introduces a wrapper for a new raw_setsockopt_locked() function analogue to the isotp_setsockopt[_locked]() approach in net/can/isotp.c [mkl: use Closes tag instead of Link]
Quoted source text, attributed separately from HOL analysis.