{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72123","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.907Z","datePublished":"2026-08-15T05:53:01.433Z","dateUpdated":"2026-08-19T16:36:18.988Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-19T16:36:18.988Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF\n\nCommit f1b4e32aca08 (\"can: bcm: use call_rcu() instead of costly\nsynchronize_rcu()\") replaced synchronize_rcu() in bcm_delete_rx_op()\nwith call_rcu() and introduced the RX_NO_AUTOTIMER flag.\n\nHowever, this flag check was omitted for thrtimer in the packet rx\nfast-path. During BCM RX operation teardown, a concurrent RCU reader\n(bcm_rx_handler) can race and re-arm thrtimer via\nbcm_rx_update_and_send() after call_rcu() has been scheduled.  Once\nthe RCU grace period elapses, bcm_op is freed.  The subsequently\nfiring thrtimer then dereferences the deallocated op, causing a UAF.\n\nAdding flag checks to the rx fast-path (bcm_rx_update_and_send) does not\nfully close the TOCTOU race and introduces latency for every CAN frame.\nConversely, calling hrtimer_cancel() directly inside the RCU callback\n(softirq context) is fatal as hrtimer_cancel() can sleep, triggering\na \"scheduling while atomic\" panic.\n\nResolve this by deferring the timer cancellation and memory free to a\ndedicated unbound workqueue (bcm_wq).  The RCU callback now queues a\nwork item to bcm_wq, which safely cancels both timers and deallocates\nmemory in sleepable process context.  A dedicated workqueue is used to\nprevent system-wide WQ saturation and is cleanly flushed/destroyed\non module unload to avoid rmmod page faults.\n\nSince the deferred work can now outlive the calling context by an\nunbounded amount, also take a reference on op->sk when it is assigned\nand drop it only once the deferred work has cancelled both timers, so a\nsocket can no longer be freed out from under a still-armed timer whose\ncallback (bcm_send_to_user()) dereferences op->sk."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local BCM socket syscalls (sendmsg with RX_SETUP/SETTIMER/ival2 throttling and RX_DELETE); CAN frames can be injected locally via loopback without physical bus access.\nAC:L - The attacker controls both sides of the race by concurrently issuing RX_DELETE teardown and delivering matching CAN frames (e.g., via threads or paired BCM/RAW sockets), making the thrtimer re-arm UAF reliably triggerable.\nPR:L - No kernel capability check gates AF_CAN/CAN_BCM socket creation or bcm_sendmsg opcodes; any unprivileged local user with socket access (including via user namespaces with vcan) can reach the vulnerable path.\nUI:N - No victim interaction is required; the attacker self-triggers the race through their own BCM socket operations and locally injected CAN traffic.\nS:U - Impact is confined to kernel memory corruption and local privilege escalation within the same kernel security boundary, not a cross-boundary escape such as VM or IOMMU bypass.\nC:H - The thrtimer UAF dereferences freed bcm_op fields (locks, frame buffers, op->sk) in bcm_rx_thr_handler/bcm_send_to_user, enabling attacker-controlled heap reuse and arbitrary kernel memory disclosure.\nI:H - UAF on the bcm_op slab object allows heap spraying to corrupt function pointers, timers, and sock structures, providing a standard path to arbitrary kernel writes and local privilege escalation.\nA:H - The freed-op dereference in the hrtimer softirq path causes kernel oops/panic under normal exploitation attempts, and successful memory corruption can crash or hang the system."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/can/bcm.c"],"versions":[{"version":"85cd41070df992d3c0dfd828866fdd243d3b774a","lessThan":"de5fce46637de05bef56ec08528127676eb6fc9b","status":"affected","versionType":"git"},{"version":"f34f2a18e47b73e48f90a757e1f4aaa8c7d665a1","lessThan":"036a8c320ca11bc912e8027adcfad14b326f067e","status":"affected","versionType":"git"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"3cf4fd5316f449811d8baf1bc6978ef5a7b743a9","status":"affected","versionType":"git"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"4177762f70646ac48a2af382e45a795cbd295198","status":"affected","versionType":"git"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f","status":"affected","versionType":"git"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5","status":"affected","versionType":"git"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"ce2d4b121fb7545e1ed588e860c8e5fd5ad45224","status":"affected","versionType":"git"},{"version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","lessThan":"68973f9db76144825e4f35dfdc80fb8279eb2d57","status":"affected","versionType":"git"},{"version":"fbac09a3b8890003c0c55294c00709f3ae5501bb","status":"affected","versionType":"git"},{"version":"5b48f5711f1c630841ab78dcc061de902f0e37bf","status":"affected","versionType":"git"},{"version":"edb4baffb9483141a50fb7f7146cfe4a4c0c2db8","status":"affected","versionType":"git"},{"version":"5.10.130","lessThan":"5.10.265","status":"affected","versionType":"semver"},{"version":"5.15.54","lessThan":"5.15.216","status":"affected","versionType":"semver"},{"version":"4.19.252","lessThan":"4.20","status":"affected","versionType":"semver"},{"version":"5.4.205","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"5.18.11","lessThan":"5.19","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/can/bcm.c"],"versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","status":"unaffected","versionType":"semver"},{"version":"5.10.265","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.130","versionEndExcluding":"5.10.265"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.54","versionEndExcluding":"5.15.216"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.252"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.205"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18.11"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/de5fce46637de05bef56ec08528127676eb6fc9b"},{"url":"https://git.kernel.org/stable/c/036a8c320ca11bc912e8027adcfad14b326f067e"},{"url":"https://git.kernel.org/stable/c/3cf4fd5316f449811d8baf1bc6978ef5a7b743a9"},{"url":"https://git.kernel.org/stable/c/4177762f70646ac48a2af382e45a795cbd295198"},{"url":"https://git.kernel.org/stable/c/6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f"},{"url":"https://git.kernel.org/stable/c/cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5"},{"url":"https://git.kernel.org/stable/c/ce2d4b121fb7545e1ed588e860c8e5fd5ad45224"},{"url":"https://git.kernel.org/stable/c/68973f9db76144825e4f35dfdc80fb8279eb2d57"}],"title":"can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF","x_generator":{"engine":"bippy-1.2.0"}}}}