PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72115 Linux CVE debrief

The Linux kernel has a vulnerability, CVE-2026-72115, related to CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. This issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces, potentially causing spurious RX_TIMEOUT notifications and last_frames corruption. Affected systems may be exposed to potential attacks if not properly mitigated. Linux kernel developers and users, CAN bcm operators, and security teams should review and apply patches, monitor for suspicious activity, and ensure that the Linux kernel is up-to-date with the latest security patches. The vulnerability is related to the CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. Evidence is limited to public CVE and NVD information. Defenders should verify patch application, review CAN bcm operations, and monitor for suspicious activity.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and users, CAN bcm operators, and security teams should care about this vulnerability. They should review and apply patches, monitor for suspicious activity, and ensure that the Linux kernel is up-to-date with the latest security patches. Affected systems may be exposed to potential attacks if not properly mitigated. Vulnerability management and security teams should prioritize patching and review compensating controls for exposed systems. CAN bcm operators should verify patch application and monitor CAN bcm operations for anomalies. Linux kernel developers should review the patch and ensure it is integrated into their products. Users of Linux kernel-based systems should also be aware of the vulnerability and take steps to mitigate it, such as applying patches or using compensating controls. Security teams should review the vulnerability and assess its impact on their organization's systems and assets. They should also develop a plan to patch or mitigate the vulnerability and monitor for potential attacks. Asset inventory and configuration management may be necessary to identify affected systems. Rollback change windows and source tracking may also be required to ensure that patches are applied and verified. Monitoring and detection capabilities should be reviewed to ensure that potential attacks are detected and responded to promptly. Compensating controls, such as network segmentation or access controls, may be necessary to mitigate the vulnerability while patches are being applied. Vendor patch guidance and exposure review should be followed to ensure that patches are applied correctly and that the vulnerability is properly mitigated. The vulnerability management process should be reviewed to ensure that similar vulnerabilities are identified and addressed promptly in the future. The security team should also review the CVE and NVD information to understand the vulnerability and its potential impact on their systems and assets. They should also review the Linux kernel patch and ensure that it is properly integrated into their systems. The security team should also develop a plan to monitor for potential attacks and respond to them in a

Technical summary

The Linux kernel has a vulnerability that has been resolved, related to CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. The issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces. This can cause spurious RX_TIMEOUT notifications and last_frames corruption. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog.

Defensive priority

High

Recommended defensive actions

  • Review and apply the patch for the Linux kernel vulnerability
  • Monitor for any suspicious activity related to CAN bcm operations
  • Ensure that the Linux kernel is up-to-date with the latest security patches
  • Perform compensating controls review for exposed systems
  • Conduct asset inventory to identify affected systems
  • Implement rollback/change windows for patch application
  • Track source and verify patch application

Evidence notes

The vulnerability is related to the CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. The issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces. Evidence is limited to public CVE and NVD information. Defenders should verify patch application, review CAN bcm operations, and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72115 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72115

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72115 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72115

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/18b45251e74e35668f0dd0c470549384ae191ecf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2f5976f54a04e9f18b25283036ac3136be453b17

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3ff8c24b421070a2db99a5cdb86edc9ff339418e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b6317022b685a430a3ae420456716e3c0c02ef4b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/eca8b44d51fc6ab61022258ec968e55e3073b79e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.