CVE-2026-72124
Race condition in Linux CAN ISO-TP TX state can corrupt transfers or cause DoS.
Is CVE-2026-72124 being exploited?
Not confirmed. CVE-2026-72124 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.35% probability of exploitation in the next 30 days.
How severe is CVE-2026-72124?
CVE-2026-72124 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-72124?
Yes. A fix has been recorded for CVE-2026-72124. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-72124 affect?
CVE-2026-72124 affects Linux kernel (CAN ISO-TP module), Embedded Linux devices with CAN bus (vehicles, gateways, PLCs). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-72124?
Apply the Linux kernel fix for ISO-TP and restart CAN services; update embedded device firmware.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local or on-bus attackers can trigger TX state races, causing message corruption, failed/duplicated transfers, or kernel-level denial of service.
Patch when possible
- affected>= e057dd3fc20ffb3d7f150af46542a51b59b90127 and < bbedeb67a9a684f2fb78c55bd3662c400526715e
- affected>= e057dd3fc20ffb3d7f150af46542a51b59b90127 and < 377a8f500704da42ed86a4541ed930e9dcfdb2ea
- affected>= e057dd3fc20ffb3d7f150af46542a51b59b90127 and < 6da8119e8dd542194103139812d1a4b7dcd1aedd
- affected>= e057dd3fc20ffb3d7f150af46542a51b59b90127 and < 0b05eca9589f609e2491b528dccf683168a4cda8
- affected>= e057dd3fc20ffb3d7f150af46542a51b59b90127 and < a7d90e7b5e75d7406c889fe36e9a61ee364a00cb
- affected>= e057dd3fc20ffb3d7f150af46542a51b59b90127 and < 37beb16e08cae94cc05840c7274225e3b0b38ae7
- affected>= e057dd3fc20ffb3d7f150af46542a51b59b90127 and < 4f1fdf1a1c317bcac0c6b6c8e12642c9983de1ca
- affected>= e057dd3fc20ffb3d7f150af46542a51b59b90127 and < cf070fe33bfbd1a4c21236078fadb35dd223a157
- affected5.10
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.