CVE-2026-23362
can: bcm: fix locking for bcm_op runtime updates
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix locking for bcm_op runtime updates Commit c2aba69d0c36 ("can: bcm: add locking for bcm_op runtime updates")
added a locking for some variables that can be modified at runtime when
updating the sending bcm_op with a new TX_SETUP command in bcm_tx_setup(). Usually the RX_SETUP only handles and filters incoming traffic with one
exception: When the RX_RTR_FRAME flag is set a predefined CAN frame is
sent when a specific RTR frame is received. Therefore the rx bcm_op uses
bcm_can_tx() which uses the bcm_tx_lock that was only initialized in
bcm_tx_setup(). Add the missing spin_lock_init() when allocating the
bcm_op in bcm_rx_setup() to handle the RTR case properly.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2026-01-13 CVE Reserved
- 2026-03-25 CVE Published
- 2026-04-26 EPSS Updated
- 2026-05-11 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (16)
| URL | Tag | Source |
|---|---|---|
| https://git.kernel.org/stable/c/7595de7bc56e0e52b74e56c90f7e247bf626d628 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/fbd8fdc2b218e979cfe422b139b8f74c12419d1f | Vuln. Introduced | |
| https://git.kernel.org/stable/c/2a437b86ac5a9893c902f30ef66815bf13587bf6 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/76c84c3728178b2d38d5604e399dfe8b0752645e | Vuln. Introduced | |
| https://git.kernel.org/stable/c/cc55dd28c20a6611e30596019b3b2f636819a4c0 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/8f1c022541bf5a923c8d6fa483112c15250f30a4 | Vuln. Introduced | |
| https://git.kernel.org/stable/c/c4e8a172501e677ebd8ea9d9161d97dc4df56fbd | Vuln. Introduced |
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.10.238 < 5.10.253 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.10.238 < 5.10.253" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.15.185 < 5.15.203 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.15.185 < 5.15.203" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.1.141 < 6.1.167 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.1.141 < 6.1.167" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.6.93 < 6.6.130 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.6.93 < 6.6.130" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.12.31 < 6.12.77 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.12.31 < 6.12.77" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.15 < 6.18.17 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.15 < 6.18.17" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.15 < 6.19.7 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.15 < 6.19.7" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 6.15 < 7.0 Search vendor "Linux" for product "Linux Kernel" and version " >= 6.15 < 7.0" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 5.4.294 Search vendor "Linux" for product "Linux Kernel" and version "5.4.294" | en |
Affected
| ||||||
| Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | 6.14.9 Search vendor "Linux" for product "Linux Kernel" and version "6.14.9" | en |
Affected
| ||||||
