Answer in brief
CVE-2026-72114 records a Unknown severity vulnerability in can: bcm: validate frame length in bcm_rx_setup() for RTR replies. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <7d966cdee006911d3957e1a4e72cb93c39cd8c1e || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <1b475c0c72f44622a320a4386ce9e76f85e69bc7 || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <deb6a697cce3f021e731df543597f37a5e54caab || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <59bfddea64159594feb62ef11b7d7a33c8ee3783 || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <62ec41f364648be79d54d94d0d240ee326948afd | 7d966cdee006911d3957e1a4e72cb93c39cd8c1e, 1b475c0c72f44622a320a4386ce9e76f85e69bc7, deb6a697cce3f021e731df543597f37a5e54caab, 59bfddea64159594feb62ef11b7d7a33c8ee3783, 62ec41f364648be79d54d94d0d240ee326948afd |
| Linux/Linuxgeneric | 2.6.25 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: can: bcm: validate frame length in bcm_rx_setup() for RTR replies bcm_tx_setup() validates cf->len against the CAN/CAN FD DLC limits before installing frames for TX_SETUP, but bcm_rx_setup() never did the same for the RTR-reply frame configured via RX_SETUP with RX_RTR_FRAME.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-72114 records a Unknown severity vulnerability in can: bcm: validate frame length in bcm_rx_setup() for RTR replies. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <7d966cdee006911d3957e1a4e72cb93c39cd8c1e || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <1b475c0c72f44622a320a4386ce9e76f85e69bc7 || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <deb6a697cce3f021e731df543597f37a5e54caab || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <59bfddea64159594feb62ef11b7d7a33c8ee3783 || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <62ec41f364648be79d54d94d0d240ee326948afd | 7d966cdee006911d3957e1a4e72cb93c39cd8c1e, 1b475c0c72f44622a320a4386ce9e76f85e69bc7, deb6a697cce3f021e731df543597f37a5e54caab, 59bfddea64159594feb62ef11b7d7a33c8ee3783, 62ec41f364648be79d54d94d0d240ee326948afd |
| Linux/Linuxgeneric | 2.6.25 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: can: bcm: validate frame length in bcm_rx_setup() for RTR replies bcm_tx_setup() validates cf->len against the CAN/CAN FD DLC limits before installing frames for TX_SETUP, but bcm_rx_setup() never did the same for the RTR-reply frame configured via RX_SETUP with RX_RTR_FRAME.
Quoted source text, attributed separately from HOL analysis.