CVE-2026-23155
published 2026-02-14CVE-2026-23155: In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message Sinc commit 79a6d1bfe114…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.8th percentile
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback():
unanchor URL on usb_submit_urb() error") a failing resubmit URB will print
an info message.
In the case of a short read where netdev has not yet been assigned,
initialize as NULL to avoid dereferencing an undefined value. Also report
the error value of the failed resubmit.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.9-1 (forky) | linux 6.18.9-1 (forky) |
| linux | linux | >= 6.12.68 < 6.12.69 | 6.12.69 |
| linux | linux | >= 6.18.8 < 6.18.9 | 6.18.9 |
| linux | linux | >= 6.6.122 < 6.6.123 | 6.6.123 |
| linux | linux | >= 79a6d1bfe1148bc921b8d7f3371a7fbce44e30f7 < 494fc029f662c331e06b7c2031deff3c64200eed | 494fc029f662c331e06b7c2031deff3c64200eed |
| linux | linux | >= aa8a8866c533a150be4763bcb27993603bd5426c < aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5 | aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5 |
| linux | linux | >= c3edc14da81a8d8398682f6e4ab819f09f37c0b7 < 713ba826ae114ab339c9a1b31e209bebdadb0ac9 | 713ba826ae114ab339c9a1b31e209bebdadb0ac9 |
| linux | linux | >= c610b550ccc0438d456dfe1df9f4f36254ccaae3 < 8986cdf52f86208df9c7887fee23365b5d37da26 | 8986cdf52f86208df9c7887fee23365b5d37da26 |
| linux | linux | >= ce4352057fc5a986c76ece90801b9755e7c6e56c < 923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6 | 923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6 |
| linux | linux | >= da01de754e455e2598a7f1ce4ff2078c4f0ecde1 < 7a431df418ee6b79841e0b4c7c265a791e3d0a75 | 7a431df418ee6b79841e0b4c7c265a791e3d0a75 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.18.9-1 | 6.18.9-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.6.122/6.12.68/6.18.8 gs_usb_receive_bulk_callback information exposure (Nessus ID 299217 / WID-SEC-2026-0421)
vuldb·2026-08-08·CVSS 5.5
CVE-2026-23155 [MEDIUM] Linux Kernel up to 6.6.122/6.12.68/6.18.8 gs_usb_receive_bulk_callback information exposure (Nessus ID 299217 / WID-SEC-2026-0421)
A vulnerability described as critical has been identified in Linux Kernel up to 6.6.122/6.12.68/6.18.8. This vulnerability affects the function gs_usb_receive_bulk_callback. The manipulation results in information exposure through error message.
This vulnerability was named CVE-2026-23155. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
GHSA
GHSA-qrjv-2grw-rfj4: In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
Sinc commit 79a6d
ghsa_unreviewed·2026-02-14
CVE-2026-23155 [MEDIUM] CWE-476 GHSA-qrjv-2grw-rfj4: In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
Sinc commit 79a6d
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback():
unanchor URL on usb_submit_urb() error") a failing resubmit URB will print
an info message.
In the case of a short read where netdev has not yet been assigned,
initialize as NULL to avoid dereferencing an undefined value. Also report
the error value of the failed resubmit.
OSV
CVE-2026-23155: In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message Sinc commit 79a6d1b
osv·2026-02-14·CVSS 5.5
CVE-2026-23155 [MEDIUM] CVE-2026-23155: In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message Sinc commit 79a6d1b
In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error") a failing resubmit URB will print an info message. In the case of a short read where netdev has not yet been assigned, initialize as NULL to avoid dereferencing an undefined value. Also report the error value of the failed resubmit.
Red Hat
kernel: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
vendor_redhat·2026-02-14·CVSS 5.5
CVE-2026-23155 [MEDIUM] CWE-824 kernel: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
kernel: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback():
unanchor URL on usb_submit_urb() error") a failing resubmit URB will print
an info message.
In the case of a short read where netdev has not yet been assigned,
initialize as NULL to avoid dereferencing an undefined value. Also report
the error value of the failed resubmit.
A potential use of uninitialized variable was found in the gs_usb CAN driver. When a short read occurs before the netdev has been assigned, the error message code could dereference an undefined netdev pointer value, potentially causing a crash or inf
Debian
CVE-2026-23155: linux - In the Linux kernel, the following vulnerability has been resolved: can: gs_usb...
vendor_debian·2026·CVSS 5.5
CVE-2026-23155 [MEDIUM] CVE-2026-23155: linux - In the Linux kernel, the following vulnerability has been resolved: can: gs_usb...
In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error") a failing resubmit URB will print an info message. In the case of a short read where netdev has not yet been assigned, initialize as NULL to avoid dereferencing an undefined value. Also report the error value of the failed resubmit.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.18.9-1)
sid: resolved (fixed in 6.18.9-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23155 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-23155 [MEDIUM] CVE-2026-23155 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23155 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback():
unanchor URL on usb_submit_urb() error") a failing resubmit URB will print
an info message.
In the case of a short read where netdev has not yet been assigned,
initialize as NULL to avoid dereferencing an undefined value. Also report
the error value of the failed resubmit.
Source : NVD
## 5.5
Score
Published February 14, 2026
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Explo
Bugzilla
CVE-2026-23155 kernel: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
bugzilla·2026-02-14·CVSS 5.5
CVE-2026-23155 [MEDIUM] CVE-2026-23155 kernel: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
CVE-2026-23155 kernel: can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
In the Linux kernel, the following vulnerability has been resolved:
can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
Sinc commit 79a6d1bfe114 ("can: gs_usb: gs_usb_receive_bulk_callback():
unanchor URL on usb_submit_urb() error") a failing resubmit URB will print
an info message.
In the case of a short read where netdev has not yet been assigned,
initialize as NULL to avoid dereferencing an undefined value. Also report
the error value of the failed resubmit.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026021415-CVE-2026-23155-32be@gregkh/T
https://git.kernel.org/stable/c/494fc029f662c331e06b7c2031deff3c64200eedhttps://git.kernel.org/stable/c/713ba826ae114ab339c9a1b31e209bebdadb0ac9https://git.kernel.org/stable/c/7a431df418ee6b79841e0b4c7c265a791e3d0a75https://git.kernel.org/stable/c/8986cdf52f86208df9c7887fee23365b5d37da26https://git.kernel.org/stable/c/923379f1d7e3af8ccbf11edbbcf41f1bb3e9cfe6https://git.kernel.org/stable/c/aed58a28ea71a0d7d0947190fab1e3f4daa1d4a5
2026-02-14
Published