cbcvebase.
CVE-2026-23324
published 2026-03-25

CVE-2026-23324: In the Linux kernel, the following vulnerability has been resolved: can: usb: etas_es58x: correctly anchor the urb in the read bulk callback When submitting an…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: can: usb: etas_es58x: correctly anchor the urb in the read bulk callback When submitting an urb, that is using the anchor pattern, it needs to be anchored before submitting it otherwise it could be leaked if usb_kill_anchored_urbs() is called. This logic is correctly done elsewhere in the driver, except in the read bulk callback so do that here also.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 8537257874e949a59c834cecfd5a063e11b64b0b < 7a0171b4921ad443fee5ed4fcb9d99fa4776edac7a0171b4921ad443fee5ed4fcb9d99fa4776edac
linuxlinux>= 8537257874e949a59c834cecfd5a063e11b64b0b < 2185ea6e4ebcb61d1224dc7d187c59723cb5ad592185ea6e4ebcb61d1224dc7d187c59723cb5ad59
linuxlinux>= 8537257874e949a59c834cecfd5a063e11b64b0b < f6e90c113c92e83fc0963d5e60e16b0e8a268981f6e90c113c92e83fc0963d5e60e16b0e8a268981
linuxlinux>= 8537257874e949a59c834cecfd5a063e11b64b0b < b878444519fa03a3edd287d1963cf79ef78be2f1b878444519fa03a3edd287d1963cf79ef78be2f1
linuxlinux>= 8537257874e949a59c834cecfd5a063e11b64b0b < 18eee279e9b5bff0db1aca9475ae4bc12804f05c18eee279e9b5bff0db1aca9475ae4bc12804f05c
linuxlinux>= 8537257874e949a59c834cecfd5a063e11b64b0b < b8f9ca88253574638bcff38900a4c28d570b1919b8f9ca88253574638bcff38900a4c28d570b1919
linuxlinux>= 8537257874e949a59c834cecfd5a063e11b64b0b < 5eaad4f768266f1f17e01232ffe2ef009f8129b75eaad4f768266f1f17e01232ffe2ef009f8129b7
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 5.13.0 < 6.1.1676.1.167
linuxlinux_kernel>= 5.13.1 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
linuxlinux_kernel>= 6.7.0 < 6.12.776.12.77
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
ubuntulinux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.