PT-2026-8150 · Linux · Linux Kernel

Published

2026-01-01

·

Updated

2026-03-26

·

CVE-2026-23155

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s CAN (Controller Area Network) subsystem, specifically within the gs usb receive bulk callback() function. A commit introduced an issue where a failing resubmit URB (USB Request Block) would print an info message instead of an error. This could lead to incorrect error handling, particularly during short reads when the network device has not yet been assigned, potentially causing a dereference of an undefined value. The issue was addressed with commit 79a6d1bfe114.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-23155
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1

Affected Products

Linux Kernel