PT-2026-27727 · Broadcom+3 · Broadcom Nan+3

CVE-2026-23362

·

Published

2026-01-01

·

Updated

2026-08-30

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s CAN (Controller Area Network) subsystem, specifically within the Broadcom CAN (bcm) driver. A missing spinlock initialization in the bcm rx setup() function when allocating the bcm op structure can lead to issues when handling Remote Transmission Request (RTR) frames. The vulnerability occurs because the bcm tx lock is only initialized in bcm tx setup(), but the RX setup also uses bcm can tx() in the case of receiving an RTR frame. This can cause problems when updating the sending bcm op with a new TX SETUP command. The commit c2aba69d0c36 aimed to add locking for runtime updates but did not fully address the initialization issue in the RX path. The vulnerable code is related to the bcm rx setup() and bcm tx setup() functions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12477
CVE-2026-23362
ECHO-F499-5A3E-5F7A
OESA-2026-1862
OESA-2026-1863
OESA-2026-1864
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:1668-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8665-1
USN-8668-1

Affected Products

Broadcom Nan
Linuxmint
Linux Kernel
Ubuntu