cbcvebase.
CVE-2026-23362
published 2026-03-25

CVE-2026-23362: In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix locking for bcm_op runtime updates Commit c2aba69d0c36 ("can: bcm: add…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.10%
0.8th percentile
In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix locking for bcm_op runtime updates Commit c2aba69d0c36 ("can: bcm: add locking for bcm_op runtime updates") added a locking for some variables that can be modified at runtime when updating the sending bcm_op with a new TX_SETUP command in bcm_tx_setup(). Usually the RX_SETUP only handles and filters incoming traffic with one exception: When the RX_RTR_FRAME flag is set a predefined CAN frame is sent when a specific RTR frame is received. Therefore the rx bcm_op uses bcm_can_tx() which uses the bcm_tx_lock that was only initialized in bcm_tx_setup(). Add the missing spin_lock_init() when allocating the bcm_op in bcm_rx_setup() to handle the RTR case properly.

Affected

73 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 2a437b86ac5a9893c902f30ef66815bf13587bf6 < 800f26f11ae37b17f58e0001f28a47dd75c26557800f26f11ae37b17f58e0001f28a47dd75c26557
linuxlinux>= 5.10.238 < 5.10.2535.10.253
linuxlinux>= 5.15.185 < 5.15.2035.15.203
linuxlinux>= 5.4.294 < 5.55.5
linuxlinux>= 6.1.141 < 6.1.1676.1.167
linuxlinux>= 6.12.31 < 6.12.776.12.77
linuxlinux>= 6.14.9 < 6.156.15
linuxlinux>= 6.6.93 < 6.6.1306.6.130
linuxlinux>= 7595de7bc56e0e52b74e56c90f7e247bf626d628 < 0904037e713f787d1376e1d349c3bdf6c31058810904037e713f787d1376e1d349c3bdf6c3105881
linuxlinux>= 76c84c3728178b2d38d5604e399dfe8b0752645e < 70e951afad4c025261fe3c952d2b07237e320a0170e951afad4c025261fe3c952d2b07237e320a01
linuxlinux>= c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 < 8215ba7bc99e84e66fd6938874ec4330a9d965188215ba7bc99e84e66fd6938874ec4330a9d96518
linuxlinux>= c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 < f0c349b2c21b220af5ba19f29b885e222958d796f0c349b2c21b220af5ba19f29b885e222958d796
linuxlinux>= c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 < c35636e91e392e1540949bbc67932167cb48bc3ac35636e91e392e1540949bbc67932167cb48bc3a
linuxlinux>= cc55dd28c20a6611e30596019b3b2f636819a4c0 < 8bcf2d847adb82b2c617456f6da17ac5e6c752858bcf2d847adb82b2c617456f6da17ac5e6c75285
linuxlinux>= fbd8fdc2b218e979cfe422b139b8f74c12419d1f < c85b96eaf766d8f066b1139a17a51efa2f6627efc85b96eaf766d8f066b1139a17a51efa2f6627ef
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 0 < 6.1.1676.1.167
linuxlinux_kernel>= 5.10.238 < 5.10.2535.10.253
linuxlinux_kernel>= 5.15.185 < 5.15.2035.15.203

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.