Executive brief
The Linux kernel's CAN (Controller Area Network) BCM module manages broadcast/multicast operations for vehicle diagnostics and automation. A race condition exists where list operations are not properly synchronized, allowing concurrent readers (via procfs) to traverse incomplete or freed data structures. This can cause kernel crashes or information disclosure.
Technical details
The vulnerability is a race condition in net/can/bcm.c affecting RCU (Read-Copy-Update) list synchronization. The bcm_[rx|tx]_setup() functions were adding bcm_op structures to lists using non-RCU-safe list_add() instead of list_add_rcu(), allowing bcm_proc_show() to traverse partially-initialized structures under rcu_read_lock(). Additionally, bcm_release() was freeing operations via call_rcu() without first unlinking them via list_del_rcu(). The fix moves list_add_rcu() calls to after complete initialization and adds proper list_del_rcu() before removal. Affected kernel versions range from those introducing the vulnerable code (via commit dac5e6249159) through current; exploitability requires local access to trigger concurrent list traversal and modification.
Affected products
- Linux Linux kernel Multiple versions (see git.kernel.org commits)
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched