cbcvebase.
CVE-2026-23061
published 2026-02-04

CVE-2026-23061: In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak Fix similar memory…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.5th percentile
In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak Fix similar memory leak as in commit 7352e1d5932a ("can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak"). In kvaser_usb_set_{,data_}bittiming() -> kvaser_usb_setup_rx_urbs(), the URBs for USB-in transfers are allocated, added to the dev->rx_submitted anchor and submitted. In the complete callback kvaser_usb_read_bulk_callback(), the URBs are processed and resubmitted. In kvaser_usb_remove_interfaces() the URBs are freed by calling usb_kill_anchored_urbs(&dev->rx_submitted). However, this does not take into account that the USB framework unanchors the URB before the complete function is called. This means that once an in-URB has been completed, it is no longer anchored and is ultimately not released in usb_kill_anchored_urbs(). Fix the memory leak by anchoring the URB in the kvaser_usb_read_bulk_callback() to the dev->rx_submitted anchor.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 080f40a6fa28dab299da7a652e444b1e2d9231e7 < d9d824582f2ec76459ffab449e9b05c7bc49645cd9d824582f2ec76459ffab449e9b05c7bc49645c
linuxlinux>= 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 40a3334ffda479c63e416e61ff086485e24401f740a3334ffda479c63e416e61ff086485e24401f7
linuxlinux>= 080f40a6fa28dab299da7a652e444b1e2d9231e7 < c1b39fa24c140bc616f51fef4175c1743e2bb132c1b39fa24c140bc616f51fef4175c1743e2bb132
linuxlinux>= 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 7c308f7530bffafa994e0aa8dc651a312f4b9ff47c308f7530bffafa994e0aa8dc651a312f4b9ff4
linuxlinux>= 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 94a7fc42e21c7d9d1c49778cd1db52de5df52a0194a7fc42e21c7d9d1c49778cd1db52de5df52a01
linuxlinux>= 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 3b1a593eab941c3f32417896cc7df564191f24823b1a593eab941c3f32417896cc7df564191f2482
linuxlinux>= 080f40a6fa28dab299da7a652e444b1e2d9231e7 < 248e8e1a125fa875158df521b30f2cc7e27eeeaa248e8e1a125fa875158df521b30f2cc7e27eeeaa
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 3.8 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.86.18.8
linuxlinux_kernel>= 6.2 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7 < 6.12.686.12.68
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.