CVE-2026-17523: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet This patch switches the timer to HRTIMER_MODE_SOFT, which executed the timer callback in softirq context and removes the hrtimer_tasklet.

Affected products

  • Linux Linux Kernel: from 2.6.29.1, before 4.19.226 (fixed in 4.19.226); from 4.20, before 5.4 (fixed in 5.4); version 2.6.29 only

Published 2026-07-27. Last modified 2026-10-02.