Description
In the Linux kernel, the following vulnerability has been resolved:

can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet

This patch switches the timer to HRTIMER_MODE_SOFT, which executed the
timer callback in softirq context and removes the hrtimer_tasklet.
Published: 2026-07-27
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel instability or denial of service
Action: Kernel Update
AI Analysis

Impact

The fault involves timer handling in the Broadcom (BCM) driver of the Linux kernel. A bug existed where the timer was scheduled in a mode that executed the callback via a tasklet, potentially leading to inappropriate scheduling or interrupt context usage. The vendor applied a fix that switches the timer to HRTIMER_MODE_SOFT, causing the callback to run in softirq context and removes the hrtimer_tasklet. This alteration mitigates the risk of driver instability or a kernel crash that could occur when the timer logic misbehaves.

Affected Systems

All Linux kernel builds that contain the unpatched BCM driver code before the availability of the change are potentially affected. Linux kernel products from the Linux community are the relevant vendor and product. Version specifics are not supplied in the provided data; the vulnerability applies to any kernel version where the relevant BCM driver code appears prior to the patch commit.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as medium‑to‑high severity. The EPSS score of less than 1% indicates that the likelihood of active exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. No remote attack vector is documented; to exploit the flaw an attacker would likely need kernel or privileged access, implying a local privilege escalation or denial‑of‑service scenario.

Generated by OpenCVE AI on September 10, 2026 at 10:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the running kernel to a version that includes the BCM driver timer fix.
  • If a release upgrade is not immediately available, backport the patch that changes the timer to HRTIMER_MODE_SOFT and removes hrtimer_tasklet.
  • As a temporary measure, unload or disable the BCM driver module until the kernel is updated.

Generated by OpenCVE AI on September 10, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-790

Thu, 10 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Thu, 10 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-754

Thu, 10 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 09 Sep 2026 08:30:00 +0000


Wed, 09 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system. In the Linux kernel, the following vulnerability has been resolved: can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet This patch switches the timer to HRTIMER_MODE_SOFT, which executed the timer callback in softirq context and removes the hrtimer_tasklet.
Title Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges can: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet
CPEs cpe:/a:redhat:enterprise_linux:8::crb
cpe:/a:redhat:enterprise_linux:8::nfv
cpe:/a:redhat:enterprise_linux:8::realtime
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8::baseos
cpe:/o:redhat:enterprise_linux:9
cpe:/o:redhat:rhel_e4s:8.8::baseos
cpe:/o:redhat:rhel_tus:8.8::baseos
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Redhat rhel E4s
Redhat rhel Tus
References

Tue, 01 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
Redhat rhel Tus
CPEs cpe:/o:redhat:rhel_e4s:8.8::baseos
cpe:/o:redhat:rhel_tus:8.8::baseos
Vendors & Products Redhat rhel E4s
Redhat rhel Tus
References

Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:8::crb
cpe:/o:redhat:enterprise_linux:8::baseos
References

Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:8::nfv
cpe:/a:redhat:enterprise_linux:8::realtime
References

Wed, 29 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system. A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
Vendors & Products Linux
Linux linux Kernel

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.
Title Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-825
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Linux Linux Kernel
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-10T13:31:17.266Z

Reserved: 2026-07-27T08:19:11.242Z

Link: CVE-2026-17523

cve-icon Vulnrichment

Updated: 2026-07-27T13:44:29.321Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-27T10:16:36.270

Modified: 2026-09-10T14:17:00.323

Link: CVE-2026-17523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T11:00:10Z

Weaknesses
  • CWE-790

    Improper Filtering of Special Elements