Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-72119— can: bcm: extend bcm_tx_lock usage for data and timer updates

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于CAN bcm模块中bcm_tx_lock锁使用不当,在数据更新和定时器更新时存在竞争条件,可能导致bcm_can_tx()和bcm_tx_timeout_handler()观察到部分更新或未验证的帧。

CVSS 7.8 · High EPSS 0.16% · P6

Affected Version Matrix 27

VendorProduct Version RangeStatus
Linux Linux 7595de7bc56e0e52b74e56c90f7e247bf626d628< a538b072ee074c9b41b9d9c15a6861a963e30755 affected
fbd8fdc2b218e979cfe422b139b8f74c12419d1f< 63422347b4c782f429748b2a09cd3cf3b77e6abd affected
2a437b86ac5a9893c902f30ef66815bf13587bf6< 37917e432e50b7de2b64230974380132a30f7270 affected
76c84c3728178b2d38d5604e399dfe8b0752645e< 52f06e7603780de100233713ddaf971d422e10ef affected
cc55dd28c20a6611e30596019b3b2f636819a4c0< 972fd66bb08fdef1090abe43196ca8da07216d13 affected
c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7< bd46f55dec608daa44b45dcf3328517630ad8e40 affected
c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7< 337f966c00662d81ad82cf5a4bbb150b2e32c0d4 affected
c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7< 12ce799f7ab1e05bd8fbf79e46f403bfe5597ebc affected
… +19 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-72119

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
can: bcm: extend bcm_tx_lock usage for data and timer updates
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: can: bcm: extend bcm_tx_lock usage for data and timer updates Stage new CAN frame content for an existing tx op into a kmalloc()'d buffer and validate it there, mirroring the approach already used in bcm_rx_setup(). Only copy the validated data into op->frames while holding op->bcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler() can no longer observe a partially updated or unvalidated frame. Add a missing error path for memcpy_from_msg() when copying CAN frame data from userspace. Also move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup() under op->bcm_tx_lock, and read kt_ival1/kt_ival2/count under the same lock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the torn 64-bit ktime_t read on 32-bit platforms.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一个操作系统内核。 Linux kernel存在安全漏洞,该漏洞源于CAN bcm模块中bcm_tx_lock锁使用不当,在数据更新和定时器更新时存在竞争条件,可能导致bcm_can_tx()和bcm_tx_timeout_handler()观察到部分更新或未验证的帧。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 7595de7bc56e0e52b74e56c90f7e247bf626d628 ~ a538b072ee074c9b41b9d9c15a6861a963e30755 -
Linux Linux 6.15 -

II. Public POCs for CVE-2026-72119

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-72119

登录查看更多情报信息。

Patches & Fixes for CVE-2026-72119 (8)

Same Patch Batch · Linux · 2026-08-15 · 845 CVEs total

CVE-2026-74475 10.0 CRITICAL vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74280 10.0 CRITICAL crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
CVE-2026-72407 10.0 CRITICAL geneve: validate inner network offset in geneve_gro_complete()
CVE-2026-72408 10.0 CRITICAL geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint
CVE-2026-72421 10.0 CRITICAL ipv4: fib: Don't ignore error route in local/main tables.
CVE-2026-74309 10.0 CRITICAL vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
CVE-2026-74279 10.0 CRITICAL crypto: cavium/cpt - fix DMA cleanup using wrong loop index
CVE-2026-72493 9.9 CRITICAL net: serialize netif_running() check in enqueue_to_backlog()
CVE-2026-72381 9.8 CRITICAL ksmbd: fix use-after-free of fp->owner.name in durable handle owner check
CVE-2026-72393 9.8 CRITICAL eth: fbnic: don't cache shinfo across skb realloc
CVE-2026-74401 9.8 CRITICAL dlm: fix add msg handle in send_queue ordered
CVE-2026-74406 9.8 CRITICAL vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
CVE-2026-72355 9.8 CRITICAL netfs: Fix barriering when walking subrequest list
CVE-2026-72339 9.8 CRITICAL qede: fix off-by-one in BD ring consumption on build_skb failure
CVE-2026-72211 9.8 CRITICAL ntfs: grow index root value before reparent header update
CVE-2026-72194 9.8 CRITICAL fs/ntfs3: add depth limit to indx_find_buffer to prevent stack overflow
CVE-2026-72351 9.8 CRITICAL gue: validate REMCSUM private option length
CVE-2026-72366 9.8 CRITICAL netfs: Fix netfs_create_write_req() to handle async cache object creation
CVE-2026-72098 9.8 CRITICAL dm-verity: fix buffer overflow in FEC calculation
CVE-2026-72083 9.8 CRITICAL scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE

Showing top 20 of 845 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-72119

No comments yet


Leave a comment