PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72115 Linux CVE debrief

The Linux kernel has a vulnerability, CVE-2026-72115, related to CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. This issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces, potentially causing spurious RX_TIMEOUT notifications and last_frames corruption. Affected systems may be exposed to potential attacks if not properly mitigated. Linux kernel developers and users, CAN bcm operators, and security teams should review and apply patches, monitor for suspicious activity, and ensure that the Linux kernel is up-to-date with the latest security patches. The vulnerability is related to the CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. Evidence is limited to public CVE and NVD information. Defenders should verify patch application, review CAN bcm operations, and monitor for suspicious activity.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and users, CAN bcm operators, and security teams should care about this vulnerability. They should review and apply patches, monitor for suspicious activity, and ensure that the Linux kernel is up-to-date with the latest security patches. Affected systems may be exposed to potential attacks if not properly mitigated. Vulnerability management and security teams should prioritize patching and review compensating controls for exposed systems. CAN bcm operators should verify patch application and monitor CAN bcm operations for anomalies. Linux kernel developers should review the patch and ensure it is integrated into their products. Users of Linux kernel-based systems should also be aware of the vulnerability and take steps to mitigate it, such as applying patches or using compensating controls. Security teams should review the vulnerability and assess its impact on their organization's systems and assets. They should also develop a plan to patch or mitigate the vulnerability and monitor for potential attacks. Asset inventory and configuration management may be necessary to identify affected systems. Rollback change windows and source tracking may also be required to ensure that patches are applied and verified. Monitoring and detection capabilities should be reviewed to ensure that potential attacks are detected and responded to promptly. Compensating controls, such as network segmentation or access controls, may be necessary to mitigate the vulnerability while patches are being applied. Vendor patch guidance and exposure review should be followed to ensure that patches are applied correctly and that the vulnerability is properly mitigated. The vulnerability management process should be reviewed to ensure that similar vulnerabilities are identified and addressed promptly in the future. The security team should also review the CVE and NVD information to understand the vulnerability and its potential impact on their systems and assets. They should also review the Linux kernel patch and ensure that it is properly integrated into their systems. The security team should also develop a plan to monitor for potential attacks and respond to them in a

Technical summary

The Linux kernel has a vulnerability that has been resolved, related to CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. The issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces. This can cause spurious RX_TIMEOUT notifications and last_frames corruption. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog.

Defensive priority

High

Recommended defensive actions

  • Review and apply the patch for the Linux kernel vulnerability
  • Monitor for any suspicious activity related to CAN bcm operations
  • Ensure that the Linux kernel is up-to-date with the latest security patches
  • Perform compensating controls review for exposed systems
  • Conduct asset inventory to identify affected systems
  • Implement rollback/change windows for patch application
  • Track source and verify patch application

Evidence notes

The vulnerability is related to the CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. The issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces. Evidence is limited to public CVE and NVD information. Defenders should verify patch application, review CAN bcm operations, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T06:21:25.900Z and has not been modified since then.