cbcvebase.
CVE-2026-23155
published 2026-02-14

CVE-2026-23155: In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message Sinc commit 79a6d1bfe114…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.8th percentile
In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error") a failing resubmit URB will print an info message. In the case of a short read where netdev has not yet been assigned, initialize as NULL to avoid dereferencing an undefined value. Also report the error value of the failed resubmit.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.9-1 (forky)linux 6.18.9-1 (forky)
linuxlinux>= 6.12.68 < 6.12.696.12.69
linuxlinux>= 6.18.8 < 6.18.96.18.9
linuxlinux>= 6.6.122 < 6.6.1236.6.123
linuxlinux>= 79a6d1bfe1148bc921b8d7f3371a7fbce44e30f7 < 494fc029f662c331e06b7c2031deff3c64200eed494fc029f662c331e06b7c2031deff3c64200eed
linuxlinux>= aa8a8866c533a150be4763bcb27993603bd5426c < aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5
linuxlinux>= c3edc14da81a8d8398682f6e4ab819f09f37c0b7 < 713ba826ae114ab339c9a1b31e209bebdadb0ac9713ba826ae114ab339c9a1b31e209bebdadb0ac9
linuxlinux>= c610b550ccc0438d456dfe1df9f4f36254ccaae3 < 8986cdf52f86208df9c7887fee23365b5d37da268986cdf52f86208df9c7887fee23365b5d37da26
linuxlinux>= ce4352057fc5a986c76ece90801b9755e7c6e56c < 923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6
linuxlinux>= da01de754e455e2598a7f1ce4ff2078c4f0ecde1 < 7a431df418ee6b79841e0b4c7c265a791e3d0a757a431df418ee6b79841e0b4c7c265a791e3d0a75
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.18.9-16.18.9-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.