HomeDefectsLIN1023-19391
Acknowledged

LIN1023-19391 : Security Advisory - linux - CVE-2026-23324

Created: Mar 26, 2026    Updated: Mar 31, 2026
Found In Version: 10.23.30.2
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  can: usb: etas_es58x: correctly anchor the urb in the read bulk callback  When submitting an urb, that is using the anchor pattern, it needs to be anchored before submitting it otherwise it could be leaked if usb_kill_anchored_urbs() is called.  This logic is correctly done elsewhere in the driver, except in the read bulk callback so do that here also.