CVE-2026-23155 addresses a bug in the Linux kernel's gs_usb CAN driver, specifically within the gs_usb_receive_bulk_callback function. The vulnerability involves a potential dereference of an uninitialized value during a short read when the netdev is not yet assigned, and an error message improvement for failed resubmissions. While no CVSS score is provided, its low EPSS and FAUCET Risk Score suggest a minimal severity, likely impacting system stability rather than offering direct exploitability for remote code execution. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.12.68, < 6.12.69CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.18.8, < 6.18.9CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.6.122, < 6.6.123CPE match | cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.6.122CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.6.122:*:*:*:*:*:*:* | ||
6.12.68CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.12.68:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.