Bug 2502866 (CVE-2026-72123) - CVE-2026-72123 kernel: can: bcm: thrtimer use-after-free during RX operation teardown
Summary: CVE-2026-72123 kernel: can: bcm: thrtimer use-after-free during RX operation ...
Keywords:
Status: NEW
Alias: CVE-2026-72123
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-20 16:48 UTC by OSIDB Bzimport
Modified: 2026-08-27 05:43 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:42919 0 None None None 2026-07-21 17:10:18 UTC
Red Hat Product Errata RHSA-2026:43307 0 None None None 2026-07-22 10:08:06 UTC
Red Hat Product Errata RHSA-2026:44694 0 None None None 2026-07-23 20:55:07 UTC

Description OSIDB Bzimport 2026-07-20 16:48:55 UTC
Use-after-free in CAN BCM due to race between RX operation teardown and thrtimer re-arm in bcm_rx_update_and_send().

can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF

Commit f1b4e32aca08 ("can: bcm: use call_rcu() instead of costly synchronize_rcu()") replaced synchronize_rcu() in bcm_delete_rx_op() with call_rcu() and introduced the RX_NO_AUTOTIMER flag.

Comment 3 errata-xmlrpc 2026-07-21 17:10:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:42919 https://access.redhat.com/errata/RHSA-2026:42919

Comment 4 errata-xmlrpc 2026-07-22 10:08:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:43307 https://access.redhat.com/errata/RHSA-2026:43307

Comment 5 errata-xmlrpc 2026-07-23 20:55:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:44694 https://access.redhat.com/errata/RHSA-2026:44694

Comment 7 Akiyoshi Kurita 2026-08-27 04:52:41 UTC
FYI:

Could you please verify the Red Hat Product Errata associations for this bug?

Bug 2502866 currently lists the following advisories as addressing CVE-2026-72123:

- RHSA-2026:42919 (RHEL 10)
- RHSA-2026:43307 (RHEL 9)
- RHSA-2026:44694 (RHEL 10.0 EUS)

However, the linked advisories do not appear to consistently list CVE-2026-72123.

Could you please confirm that the relevant CAN BCM fix is actually included in these kernel updates and that the errata associations are correct?

Upstream fix:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=68973f9db761

Comment 8 Akiyoshi Kurita 2026-08-27 05:43:49 UTC
Correction to my previous comment:

Comment 7 was incorrect. The Red Hat Product Errata associations listed in this bug are valid.

Please disregard my previous comment.

Sorry for the confusion.


Note You need to log in before you can comment on or make changes to this bug.