CVE-2026-72114
EUVD-2026-5907215.08.2026, 06:21
In the Linux kernel, the following vulnerability has been resolved: can: bcm: validate frame length in bcm_rx_setup() for RTR replies bcm_tx_setup() validates cf->len against the CAN/CAN FD DLC limits before installing frames for TX_SETUP, but bcm_rx_setup() never did the same for the RTR-reply frame configured via RX_SETUP with RX_RTR_FRAME.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
References