PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72122 Linux CVE debrief

A vulnerability in the Linux kernel's CAN (Controller Area Network) subsystem has been resolved. The issue was related to a race condition in the bcm (Broadcast Manager) protocol, which could lead to a socket bound to a specific CAN interface being silently turned into one that matches 'any' interface. This could result in unexpected behavior and potential security issues.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and maintainers, CAN subsystem users and administrators, security teams, and operators of systems using the Linux kernel's CAN subsystem should be aware of this vulnerability and take necessary actions to protect their systems. They should review and apply the patch, monitor CAN subsystem usage and logs for suspicious activity, and consider implementing additional security measures to prevent exploitation. This includes verifying the integrity of CAN interface configurations and ensuring that proper access controls are in place. Additionally, security teams should assess the potential impact on their systems and prioritize patching based on risk and exposure. Operators of critical infrastructure relying on CAN subsystems should take extra precautions to mitigate potential disruptions. Vulnerability management processes should be updated to account for this issue, and asset inventory should be reviewed to identify potentially affected systems. Collaboration with Linux kernel maintainers and CAN subsystem experts may be necessary for thorough mitigation and to stay informed about any further developments or advisories related to this vulnerability. Regular security audits and penetration testing should also be considered to identify and address any potential weaknesses in the CAN subsystem implementation. By taking these steps, organizations can enhance their security posture and reduce the risk associated with this vulnerability in the Linux kernel's CAN subsystem. Monitoring of CAN subsystem logs and network traffic can help detect potential exploitation attempts, allowing for swift response and mitigation. Implementing compensating controls, such as network segmentation or access restrictions, can also help minimize the impact of a potential exploit. Overall, a comprehensive approach to security, including timely patching, monitoring, and defensive measures, is essential to protect against this vulnerability in the Linux kernel's CAN subsystem. Security teams should also consider the potential for similar vulnerabilities in other subsystems and prioritize proactive security measures to prevent future issues. By prioritizing security and

Technical summary

The vulnerability was caused by a race condition in the bcm protocol, which could lead to a socket bound to a specific CAN interface being silently turned into one that matches 'any' interface. The fix involves moving the ifindex read and a bo->bound re-check into the locked section, ensuring that the two fields are not torn against each other. This change prevents the possibility of observing inconsistent combinations of bound and ifindex fields, thus resolving the issue. Linux kernel developers should review the patch and apply it to their systems to prevent potential security issues.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the patch to the Linux kernel
  • Monitor CAN subsystem usage and logs for suspicious activity
  • Consider implementing additional security measures to prevent exploitation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was discovered in the Linux kernel's CAN subsystem, specifically in the bcm protocol. The issue was caused by a race condition between the bcm_sendmsg() function and other functions that mutate the bo->ifindex and bo->bound fields. The fix involves moving the ifindex read and a bo->bound re-check into the locked section, ensuring that the two fields are not torn against each other.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72122 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72122

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72122 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72122

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0f6f9f95294b4cbb26ba02209e893e3bd91237c3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/35f0ac19efb1a3f6c5e12c00e475a9ec2d9c3a6d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6bcc5cd247c2934373bc2a1cdf8bf12321169543

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9e60c586faeaed80d55ab8ce2a4b8e56133bc395

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b70f1a15533afeeec5d07f20bec3f3867ab1c7b6

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b9c6ac6fb4e01b34575816066e5d3890a57b3c86

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d9b091d9d22fee81ec53fb55d2032951993ceadb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.