Answer in brief
CVE-2026-72115 records a High severity (CVSS 8.1) vulnerability in can: bcm: track a single source interface for ANYDEV timeout/throttle ops. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <18b45251e74e35668f0dd0c470549384ae191ecf || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <3ff8c24b421070a2db99a5cdb86edc9ff339418e || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <eca8b44d51fc6ab61022258ec968e55e3073b79e || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <b6317022b685a430a3ae420456716e3c0c02ef4b || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <2f5976f54a04e9f18b25283036ac3136be453b17 | 18b45251e74e35668f0dd0c470549384ae191ecf, 3ff8c24b421070a2db99a5cdb86edc9ff339418e, eca8b44d51fc6ab61022258ec968e55e3073b79e, b6317022b685a430a3ae420456716e3c0c02ef4b, 2f5976f54a04e9f18b25283036ac3136be453b17 |
| Linux/Linuxgeneric | 2.6.25 | Not reported |
| Linux/Linuxgeneric | >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <f147f48837cb1426521f5b3c3b3134c71128a25d || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <57cf104da4cf450ae9c16801a3164604b801d2cc || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <03dfe347c398fa41a7e30e8dc538f12568c183e6 || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <18b45251e74e35668f0dd0c470549384ae191ecf || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <3ff8c24b421070a2db99a5cdb86edc9ff339418e || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <eca8b44d51fc6ab61022258ec968e55e3073b79e || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <b6317022b685a430a3ae420456716e3c0c02ef4b || >=ffd980f976e7fd666c2e61bf8ab35107efd11828 <2f5976f54a04e9f18b25283036ac3136be453b17 | f147f48837cb1426521f5b3c3b3134c71128a25d, 57cf104da4cf450ae9c16801a3164604b801d2cc, 03dfe347c398fa41a7e30e8dc538f12568c183e6, 18b45251e74e35668f0dd0c470549384ae191ecf, 3ff8c24b421070a2db99a5cdb86edc9ff339418e, eca8b44d51fc6ab61022258ec968e55e3073b79e, b6317022b685a430a3ae420456716e3c0c02ef4b, 2f5976f54a04e9f18b25283036ac3136be453b17 |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: can: bcm: track a single source interface for ANYDEV timeout/throttle ops An ANYDEV rx op (ifindex == 0) with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces: bcm_rx_handler() can run concurrently for the same op on different CPUs, racing hrtimer_cancel()/ bcm_rx_starttimer() against bcm_rx_timeout_handler() and causing spurious RX_TIMEOUT notifications and last_frames corruption. The same concurrency lets throttled multiplex frames from different interfaces clobber the single rx_ifindex/rx_stamp fields shared by the op. Add op->if_detected to track the first interface that delivers a matching frame while a timeout/throttle timer is configured, and reject frames from any other interface for that op. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog. RTR-mode ops are excluded via RX_RTR_FRAME, independent of kt_ival1/kt_ival2, since those may briefly hold a stale value from an earlier non-RTR configuration. The claim is released in bcm_notify() on NETDEV_UNREGISTER and in bcm_rx_setup() when SETTIMER reconfigures the timer values. A (re-)claim is only possible on CAN devices in NETREG_REGISTERED dev->reg_state to cover the release in bcm_notify() where reg_state becomes NETREG_UNREGISTERING until synchronize_net().
Quoted source text, attributed separately from HOL analysis.