{"apiVersion":"1.0","identifier":"CVE-2026-72116","description":"In the Linux kernel, the following vulnerability has been resolved: can: bcm: fix stale rx/tx ops after device removal RX: an RX_SETUP update(!) for an existing op skipped can_rx_register() unconditionally, even when a concurrent NETDEV_UNREGISTER had already torn down its registration (op->rx_reg_dev == NULL). This silently did not re-enable frame delivery for that updated filter. bcm_rx_setup() now re-registers in that case, while leaving rx_ops with ifindex = 0 (all CAN devices) which never carry a tracked rx_reg_dev registered as-is. TX: bcm_notify() only handled bo->rx_ops on NETDEV_UNREGISTER, leaving tx_ops with an active cyclic transmission re-arming its hrtimer indefinitely to execute bcm_tx_timeout_handler(). Cancelling the hrtimer prevents the runaway timer and any injection into a later reused ifindex, since nothing else calls bcm_can_tx() for the op until an explicit TX_SETUP update re-arms it. Unlike bcm_rx_unreg(), which clears the tracked rx_reg_dev for rx_ops, the ifindex is intentionally left unchanged for tx_ops. bcm_tx_setup() always rejects ifindex 0, so clearing it would strand the op: neither a later TX_SETUP (bcm_find_op()) nor TX_DELETE (bcm_delete_tx_op()) could ever find it again, since both require an exact ifindex match.","publishedAt":"2026-08-15T06:21:26","lastModifiedAt":"2026-08-19T17:20:57","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72116","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","epssProbability":0.00181,"riskScore":0.72,"affectedProduct":"linux","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72116","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72116","en":"https://www.redsauce.net/en/cves/CVE-2026-72116","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72116","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72116","de":"https://www.redsauce.net/de/cves/CVE-2026-72116","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72116","el":"https://www.redsauce.net/el/cves/CVE-2026-72116"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72116"}}