#VU124505 Resource exhaustion in Linux kernel - CVE-2026-23347
Published: March 25, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the CAN USB driver (f81604) when handling URB (USB Request Block) anchoring in the read bulk callback. A local user can trigger improper submission of an unanchored URB to cause a denial of service.
Exploitation requires local system access and interaction with the affected USB CAN device driver.
Remediation
External links
- https://git.kernel.org/stable/c/54ee74307165b348b2fddcd7942eb48fb4ee1237
- https://git.kernel.org/stable/c/7724645c4792914cd07f36718816c5369cc57970
- https://git.kernel.org/stable/c/952caa5da10bed22be09612433964f6877ba0dde
- https://git.kernel.org/stable/c/c001214e12202338425d6dda5d2a1919d674282d
- https://git.kernel.org/stable/c/f6d80b104f904a6da922907394eec66d3e2ffc57