CVE-2026-72120: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu list annotations and operations sashiko-bot remarked the missing use of list_add_rcu() in bcm_[rx|tx]_setup() to have a proper initialized bcm_op structure when bcm_proc_show() traverses the bcm_op's under rcu_read_lock(). To cover all initial settings of the bcm_op's the list_add_rcu() calls are moved to the end of the setup code. While at it, also fix the mirroring removal side: bcm_release() called bcm_remove_op() - which frees the op via call_rcu() - on ops that were still linked in bo->tx_ops/bo->rx_ops, without list_del_rcu() first. Unlink each op with list_del_rcu() before handing it to bcm_remove_op(), matching the existing pattern in bcm_delete_tx_op()/bcm_delete_rx_op().
Affected products
- Linux Linux: from 5.10.238, before 5.10.261 (fixed in 5.10.261); from 5.15.185, before 5.15.212 (fixed in 5.15.212); from 6.1.141, before 6.1.178 (fixed in 6.1.178); from 6.6.93, before 6.6.145 (fixed in 6.6.145); from 6.12.31, before 6.12.97 (fixed in 6.12.97); from 5.4.294, before 5.5 (fixed in 5.5); …
Published 2026-08-15. Last modified 2026-08-17.