PatchSiren cyber security CVE debrief
CVE-2026-72115 Linux CVE debrief
The Linux kernel has a vulnerability, CVE-2026-72115, related to CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. This issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces, potentially causing spurious RX_TIMEOUT notifications and last_frames corruption. Affected systems may be exposed to potential attacks if not properly mitigated. Linux kernel developers and users, CAN bcm operators, and security teams should review and apply patches, monitor for suspicious activity, and ensure that the Linux kernel is up-to-date with the latest security patches. The vulnerability is related to the CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. Evidence is limited to public CVE and NVD information. Defenders should verify patch application, review CAN bcm operations, and monitor for suspicious activity.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and users, CAN bcm operators, and security teams should care about this vulnerability. They should review and apply patches, monitor for suspicious activity, and ensure that the Linux kernel is up-to-date with the latest security patches. Affected systems may be exposed to potential attacks if not properly mitigated. Vulnerability management and security teams should prioritize patching and review compensating controls for exposed systems. CAN bcm operators should verify patch application and monitor CAN bcm operations for anomalies. Linux kernel developers should review the patch and ensure it is integrated into their products. Users of Linux kernel-based systems should also be aware of the vulnerability and take steps to mitigate it, such as applying patches or using compensating controls. Security teams should review the vulnerability and assess its impact on their organization's systems and assets. They should also develop a plan to patch or mitigate the vulnerability and monitor for potential attacks. Asset inventory and configuration management may be necessary to identify affected systems. Rollback change windows and source tracking may also be required to ensure that patches are applied and verified. Monitoring and detection capabilities should be reviewed to ensure that potential attacks are detected and responded to promptly. Compensating controls, such as network segmentation or access controls, may be necessary to mitigate the vulnerability while patches are being applied. Vendor patch guidance and exposure review should be followed to ensure that patches are applied correctly and that the vulnerability is properly mitigated. The vulnerability management process should be reviewed to ensure that similar vulnerabilities are identified and addressed promptly in the future. The security team should also review the CVE and NVD information to understand the vulnerability and its potential impact on their systems and assets. They should also review the Linux kernel patch and ensure that it is properly integrated into their systems. The security team should also develop a plan to monitor for potential attacks and respond to them in a
Technical summary
The Linux kernel has a vulnerability that has been resolved, related to CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. The issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces. This can cause spurious RX_TIMEOUT notifications and last_frames corruption. The claim is decided in bcm_rx_handler() before hrtimer_cancel() touches op->timer, so a rejected frame can never disturb the claimed interface's watchdog.
Defensive priority
High
Recommended defensive actions
- Review and apply the patch for the Linux kernel vulnerability
- Monitor for any suspicious activity related to CAN bcm operations
- Ensure that the Linux kernel is up-to-date with the latest security patches
- Perform compensating controls review for exposed systems
- Conduct asset inventory to identify affected systems
- Implement rollback/change windows for patch application
- Track source and verify patch application
Evidence notes
The vulnerability is related to the CAN bcm tracking a single source interface for ANYDEV timeout/throttle operations. The issue arises when an ANYDEV rx op with an active RX timeout and/or throttle timer has no defined semantics when matching frames arrive from several interfaces. Evidence is limited to public CVE and NVD information. Defenders should verify patch application, review CAN bcm operations, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72115 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72115
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72115 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72115
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/18b45251e74e35668f0dd0c470549384ae191ecf
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2f5976f54a04e9f18b25283036ac3136be453b17
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3ff8c24b421070a2db99a5cdb86edc9ff339418e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b6317022b685a430a3ae420456716e3c0c02ef4b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/eca8b44d51fc6ab61022258ec968e55e3073b79e
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.