PatchSiren cyber security CVE debrief
CVE-2026-72113 Linux CVE debrief
The Linux kernel vulnerability, CVE-2026-72113, involves a missing device refcount for CAN filter removal in the bcm.c code. This issue can lead to a stale CAN filter pointing at the soon-to-be-freed bcm_op/socket if a concurrent NETDEV_UNREGISTER has already unlisted the device from the ifindex table. A former fix for raw.c introduced a netdevice_tracker which solves the issue for bcm.c too. Linux kernel users and administrators should verify and apply available updates to mitigate potential CAN filter removal issues. The vulnerability relies on dev_get_by_index(ifindex) to re-find the device for an rx_op before unregistering its filter.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel users and administrators, particularly those responsible for maintaining and securing Linux-based systems, should be aware of this vulnerability and take necessary precautions. This includes verifying and applying available updates, monitoring CAN filter removal and device unregistration, and implementing compensating controls for CAN filter management. Additionally, operators and platform administrators should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Vulnerability management and security teams should prioritize patching and mitigating this vulnerability to prevent potential exploitation. Those responsible for asset inventory and change management should also be aware of the potential impact on their systems and plan accordingly. This may involve reviewing compensating controls for exposed systems while remediation is scheduled and verified, checking relevant monitoring, detection, and logs for exposed assets that need extra review, and tracking exceptions and retesting remediated assets. The goal is to ensure that all necessary measures are taken to prevent potential exploitation and minimize the risk associated with this vulnerability. This requires a coordinated effort from various stakeholders, including operators, administrators, and security teams, to ensure the timely and effective mitigation of this vulnerability. By taking proactive steps to address this issue, organizations can reduce the risk of exploitation and protect their Linux-based systems from potential attacks. Furthermore, it is essential to review and update incident response plans to account for this vulnerability and ensure that all necessary procedures are in place to respond to potential security incidents. This includes identifying and prioritizing affected systems, developing and implementing patches or workarounds, and conducting thorough testing and validation to ensure the effectiveness of the mitigation measures. By prioritizing the mitigation of this vulnerability and taking proactive steps to protect their systems, organizations can minimize the risk associated with this issue and ensure the secure
Technical summary
The Linux kernel vulnerability involves a missing device refcount for CAN filter removal in the bcm.c code. A former fix for raw.c introduced a netdevice_tracker which solves the issue for bcm.c too. The vulnerability relies on dev_get_by_index(ifindex) to re-find the device for an rx_op before unregistering its filter. If a concurrent NETDEV_UNREGISTER has already unlisted the device from the ifindex table, that lookup fails and can_rx_unregister() is silently skipped, leaving a stale CAN filter pointing at the soon-to-be-freed bcm_op/socket.
Defensive priority
Linux kernel users should verify and apply available updates to mitigate potential CAN filter removal issues.
Recommended defensive actions
- Verify and apply available Linux kernel updates
- Monitor CAN filter removal and device unregistration
- Implement compensating controls for CAN filter management
- Review CAN filter configurations and update them as necessary
- Implement additional logging and monitoring for CAN filter removal events
- Verify CAN filter removal and device unregistration procedures
- Track exceptions and retest remediated assets
Evidence notes
The Linux kernel vulnerability involves a missing device refcount for CAN filter removal in the bcm.c code. A former fix for raw.c introduced a netdevice_tracker which solves the issue for bcm.c too. The vulnerability relies on dev_get_by_index(ifindex) to re-find the device for an rx_op before unregistering its filter. If a concurrent NETDEV_UNREGISTER has already unlisted the device from the ifindex table, that lookup fails and can_rx_unregister() is silently skipped, leaving a stale CAN filter pointing at the soon-to-be-freed bcm_op/socket.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72113 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72113
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72113 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72113
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/04d23061bbf18d5d81022eb21e9d32e99d24468d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/633bda66fbf309f5de5e1ad6defe8e6b1d77a20f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/84aa4807816e405c1bf87114fc63e06d244281ef
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b024c21c9066f6957b7d4a8f2037e4b000c5e041
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d59948293ea34b6337ce2b5febab8510de70048c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.