Executive brief
A memory leak vulnerability was identified in the Linux kernel's gs_usb driver, which handles communication with certain USB CAN (Controller Area Network) devices. When these devices are used, the system fails to properly release memory associated with data transfers, which could eventually lead to system instability or a crash as available memory is exhausted. This issue primarily affects industrial or automotive systems using these specific USB-to-CAN adapters.
Technical details
A memory leak exists in the gs_usb driver within the Linux kernel's CAN subsystem. In gs_can_open(), USB Request Blocks (URBs) are allocated and anchored to parent->rx_submitted. However, the USB framework automatically unanchors the URB before the gs_usb_receive_bulk_callback() completion handler is executed. Because the callback resubmitted the URB without re-anchoring it, the URBs were no longer tracked by the anchor and could not be freed by usb_kill_anchored_urbs() during gs_can_close(). An attacker or local process could potentially trigger this leak by repeatedly opening and closing the CAN interface or through continuous data reception, leading to kernel memory exhaustion. The fix involves explicitly re-anchoring the URB within the callback function before resubmission.
Affected products
- Linux Linux Kernel v6.6 and later (parent variable), earlier versions (usbcan variable)
Timeline
- 2025-12-23: other: Patch authored
- 2026-01-31: disclosed: CVE published
References
- https://git.kernel.org/stable/c/08624b7206ddb9148eeffc2384ebda2c47b6d1e9
- https://git.kernel.org/stable/c/7352e1d5932a0e777e39fa4b619801191f57e603
- https://git.kernel.org/stable/c/9c151898cc259a7784be60ba38664f42ede39b31
- https://git.kernel.org/stable/c/9f669a38ca70839229b7ba0f851820850a2fe1f7
- https://git.kernel.org/stable/c/ec5ccc2af9e5b045671f3f604b57512feda8bcc5
- https://git.kernel.org/stable/c/f905bcfa971edb89e398c98957838d8c6381c0c7
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html