CVE-2026-72121
Race condition in Linux CAN bcm driver may send stale or corrupted CAN frames.
Is CVE-2026-72121 being exploited?
Not confirmed. CVE-2026-72121 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.34% probability of exploitation in the next 30 days.
How severe is CVE-2026-72121?
CVE-2026-72121 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72121?
Yes. A fix has been recorded for CVE-2026-72121. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72121 affect?
CVE-2026-72121 affects Linux kernel bcm (CAN Broadcast Manager) driver, SocketCAN-based systems, Automotive ECUs, Industrial/embedded devices with CAN. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72121?
Apply kernel update with fix; isolate/restrict CAN bus access until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Concurrent access can overwrite timers/frames, causing stale or partially corrupted CAN replies enabling message spoofing, misbehavior or DoS on CAN networks.
Patch when possible
- affected>= 7595de7bc56e0e52b74e56c90f7e247bf626d628 and < 96994180bd7b248b0cc698afe926e23fc1bda59b
- affected>= fbd8fdc2b218e979cfe422b139b8f74c12419d1f and < caa8704a7f3cb7806331596195385437126ecb3a
- affected>= 2a437b86ac5a9893c902f30ef66815bf13587bf6 and < a7c369e7da8203e2b5be12bbcac7b9ab2ed5b658
- affected>= 76c84c3728178b2d38d5604e399dfe8b0752645e and < a7eb6db1cd3f7b556a301dc1265945ad112089f7
- affected>= cc55dd28c20a6611e30596019b3b2f636819a4c0 and < 834cbca3b12e46887f7a9b35f1981a888360ea4c
- affected>= c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 and < 19b1994069dd29478ba767de1f98f14a088198dc
- affected>= c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 and < fc9f5ee1b073bd233d9c604e338af4ebb42cbc33
- affected>= c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7 and < 749179c2e25b95d22499ed29096b3e02d6dfd2b4
- affected8f1c022541bf5a923c8d6fa483112c15250f30a4
- affectedc4e8a172501e677ebd8ea9d9161d97dc4df56fbd
- affected>= 5.10.238 and < 5.10.265
- affected>= 5.15.185 and < 5.15.216
- affected>= 6.1.141 and < 6.1.183
- affected>= 6.6.93 and < 6.6.148
- affected>= 6.12.31 and < 6.12.101
- affected>= 5.4.294 and < 5.5
- affected>= 6.14.9 and < 6.15
- affected6.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.