Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this vulnerability, prevent the `bcm` kernel module from loading if it is not required. Create a file named `/etc/modprobe.d/blacklist-bcm.conf` with the content `blacklist bcm`. A system reboot is required for this change to take effect. This mitigation may impact functionality that relies on the CAN BCM module.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Jul 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system. | A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system. |
Mon, 27 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Kernel |
|
| Vendors & Products |
Linux
Linux linux Kernel |
Mon, 27 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 27 Jul 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the kernel. An unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system. | |
| Title | Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-825 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-05T17:29:26.681Z
Reserved: 2026-07-27T08:19:11.242Z
Link: CVE-2026-17523
Updated: 2026-07-27T13:44:29.321Z
Status : Awaiting Analysis
Published: 2026-07-27T10:16:36.270
Modified: 2026-07-29T11:16:48.620
Link: CVE-2026-17523
No data.
OpenCVE Enrichment
Updated: 2026-08-03T18:00:11Z
-
CWE-825
Expired Pointer Dereference