CVE-2026-72119: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: can: bcm: extend bcm_tx_lock usage for data and timer updates Stage new CAN frame content for an existing tx op into a kmalloc()'d buffer and validate it there, mirroring the approach already used in bcm_rx_setup(). Only copy the validated data into op->frames while holding op->bcm_tx_lock, so bcm_can_tx() and bcm_tx_timeout_handler() can no longer observe a partially updated or unvalidated frame. Add a missing error path for memcpy_from_msg() when copying CAN frame data from userspace. Also move the kt_ival1/kt_ival2/ival1/ival2 updates in bcm_tx_setup() under op->bcm_tx_lock, and read kt_ival1/kt_ival2/count under the same lock in bcm_tx_set_expiry() and bcm_tx_timeout_handler(), closing the torn 64-bit ktime_t read on 32-bit platforms.
Affected products
- Linux Linux: from 5.10.238, before 5.10.265 (fixed in 5.10.265); from 5.15.185, before 5.15.216 (fixed in 5.15.216); from 6.1.141, before 6.1.183 (fixed in 6.1.183); from 6.6.93, before 6.6.148 (fixed in 6.6.148); from 6.12.31, before 6.12.101 (fixed in 6.12.101); from 5.4.294, before 5.5 (fixed in 5.5); …
Published 2026-08-15. Last modified 2026-08-19.