{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72121","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.907Z","datePublished":"2026-08-15T05:52:59.959Z","dateUpdated":"2026-08-19T16:36:16.520Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:36:16.520Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: add locking when updating filter and timer values\n\nKCSAN detected a simultaneous access to timer values that can be\noverwritten in bcm_rx_setup() when updating timer and filter content\nwhile bcm_rx_handler(), bcm_rx_timeout_handler() or bcm_rx_thr_handler()\nrun concurrently on incoming CAN traffic.\n\nProtect the timer (ival1/ival2/kt_ival1/kt_ival2/kt_lastmsg) and filter\n(nframes/flags/frames/last_frames) updates in bcm_rx_setup() with a new\nper-op bcm_rx_update_lock, taken with the matching scope in the RX\nhandlers. memcpy_from_msg() is staged into a temporary buffer before the\nlock is taken, since it can sleep and must not run under a spinlock.\n\nhrtimer_cancel() is always called without bcm_rx_update_lock held, since\nbcm_rx_timeout_handler()/bcm_rx_thr_handler() take the same lock and a\nrunning callback would otherwise deadlock against the canceller.\n\nAlso close a related race: bcm_rx_setup() cleared the RTR flag in the\nstored reply frame's can_id as a separate, unprotected step after the\nframe content was already installed, so a concurrent bcm_rx_handler()\ncould transmit a stale reply with CAN_RTR_FLAG still set. Fold that\nnormalization into the initial frame preparation instead (on the staged\nbuffer for updates, directly on op->frames pre-registration for new\nops), so the installed frame is always atomically self-consistent.\n\nbcm_rx_handler()'s RX_RTR_FRAME check now takes a lock-protected\nsnapshot of op->flags before deciding whether to call bcm_can_tx(),\nbut does not hold the lock across that call.\n\nAlso take a lock-protected snapshot of the currframe in bcm_can_tx()\nto avoid partly overwrites by content updates in bcm_tx_setup().\nFinally check if a TX_RESET_MULTI_IDX/SETTIMER might have reset\nop->currframe between the two locked sections in bcm_can_tx().\n\nOmit calling hrtimer_forward() with zero interval in bcm_rx_thr_handler().\nkt_ival2 may have been concurrently cleared by bcm_rx_setup() before it\ncancels this timer, so check kt_ival2 inside the bcm_rx_update_lock."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The race is driven by concurrent CAN frame reception in bcm_rx_handler()/timer callbacks on a shared CAN segment (automotive OBD/ECU bus, factory controllers, CAN-USB adapters), an adjacent broadcast medium comparable to Bluetooth/WiFi segment access.\nAC:L - An attacker controls both race sides by flooding RX_SETUP via sendmsg while concurrently injecting matching CAN frames or armed timers; syzbot reliably reproduced the KCSAN race without timing conditions beyond attacker control.\nPR:N - CAN_BCM sockets impose no capability checks in can_create()/bcm_sendmsg(), and a bus participant can trigger the RX handler path without any Linux credentials while racing BCM configuration updates from local services.\nUI:N - Exploitation requires no victim interaction beyond normal background CAN/BCM activity on systems that already use the Broadcast Manager for monitoring or diagnostics.\nS:U - Impact is confined to kernel memory corruption and privilege boundaries within the same host; this is not a VM escape, IOMMU bypass, or cross-authority sandbox breakout.\nC:H - Unlocked concurrent updates to nframes/flags/frames/last_frames permit torn reads and out-of-bounds accesses in handler loops and timeout memset, matching the prior BCM race class that produced KASAN slab-out-of-bounds reads.\nI:H - Partial overwrites of op->frames during bcm_can_tx(), stale RTR replies transmitted on the bus, and size-mismatched memset/memcpy against concurrently shrinking buffers enable arbitrary CAN injection and kernel heap corruption.\nA:H - Concurrent timer corruption (hrtimer_forward with zero kt_ival2), torn structure fields, and heap corruption from racing memset/copy operations can cause kernel oops, panic, or sustained denial of service on CAN-equipped systems."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/can/bcm.c"],"versions":[{"version":"7595de7bc56e0e52b74e56c90f7e247bf626d628","lessThan":"96994180bd7b248b0cc698afe926e23fc1bda59b","status":"affected","versionType":"git"},{"version":"fbd8fdc2b218e979cfe422b139b8f74c12419d1f","lessThan":"caa8704a7f3cb7806331596195385437126ecb3a","status":"affected","versionType":"git"},{"version":"2a437b86ac5a9893c902f30ef66815bf13587bf6","lessThan":"a7c369e7da8203e2b5be12bbcac7b9ab2ed5b658","status":"affected","versionType":"git"},{"version":"76c84c3728178b2d38d5604e399dfe8b0752645e","lessThan":"a7eb6db1cd3f7b556a301dc1265945ad112089f7","status":"affected","versionType":"git"},{"version":"cc55dd28c20a6611e30596019b3b2f636819a4c0","lessThan":"834cbca3b12e46887f7a9b35f1981a888360ea4c","status":"affected","versionType":"git"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"19b1994069dd29478ba767de1f98f14a088198dc","status":"affected","versionType":"git"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"fc9f5ee1b073bd233d9c604e338af4ebb42cbc33","status":"affected","versionType":"git"},{"version":"c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7","lessThan":"749179c2e25b95d22499ed29096b3e02d6dfd2b4","status":"affected","versionType":"git"},{"version":"8f1c022541bf5a923c8d6fa483112c15250f30a4","status":"affected","versionType":"git"},{"version":"c4e8a172501e677ebd8ea9d9161d97dc4df56fbd","status":"affected","versionType":"git"},{"version":"5.10.238","lessThan":"5.10.265","status":"affected","versionType":"semver"},{"version":"5.15.185","lessThan":"5.15.216","status":"affected","versionType":"semver"},{"version":"6.1.141","lessThan":"6.1.183","status":"affected","versionType":"semver"},{"version":"6.6.93","lessThan":"6.6.148","status":"affected","versionType":"semver"},{"version":"6.12.31","lessThan":"6.12.101","status":"affected","versionType":"semver"},{"version":"5.4.294","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"6.14.9","lessThan":"6.15","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/can/bcm.c"],"versions":[{"version":"6.15","status":"affected"},{"version":"0","lessThan":"6.15","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.238","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.185","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.141","versionEndExcluding":"6.1.183"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.93","versionEndExcluding":"6.6.148"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.31","versionEndExcluding":"6.12.101"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.294"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/96994180bd7b248b0cc698afe926e23fc1bda59b"},{"url":"https://git.kernel.org/stable/c/caa8704a7f3cb7806331596195385437126ecb3a"},{"url":"https://git.kernel.org/stable/c/a7c369e7da8203e2b5be12bbcac7b9ab2ed5b658"},{"url":"https://git.kernel.org/stable/c/a7eb6db1cd3f7b556a301dc1265945ad112089f7"},{"url":"https://git.kernel.org/stable/c/834cbca3b12e46887f7a9b35f1981a888360ea4c"},{"url":"https://git.kernel.org/stable/c/19b1994069dd29478ba767de1f98f14a088198dc"},{"url":"https://git.kernel.org/stable/c/fc9f5ee1b073bd233d9c604e338af4ebb42cbc33"},{"url":"https://git.kernel.org/stable/c/749179c2e25b95d22499ed29096b3e02d6dfd2b4"}],"title":"can: bcm: add locking when updating filter and timer values","x_generator":{"engine":"bippy-1.2.0"}}}}