SB20260325129 - Improper Resource Shutdown or Release in Linux kernel usb etas_es58x driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Resource Shutdown or Release (CVE-ID: CVE-2026-23324)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the USB CAN driver (etas_es58x) when handling URB (USB Request Block) anchoring in the read bulk callback. A local user can trigger improper submission of an unanchored URB to cause a denial of service.
Exploitation requires access to the CAN device interface and the ability to trigger USB read operations.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18eee279e9b5bff0db1aca9475ae4bc12804f05c
- https://git.kernel.org/stable/c/2185ea6e4ebcb61d1224dc7d187c59723cb5ad59
- https://git.kernel.org/stable/c/5eaad4f768266f1f17e01232ffe2ef009f8129b7
- https://git.kernel.org/stable/c/b878444519fa03a3edd287d1963cf79ef78be2f1
- https://git.kernel.org/stable/c/b8f9ca88253574638bcff38900a4c28d570b1919
- https://git.kernel.org/stable/c/f6e90c113c92e83fc0963d5e60e16b0e8a268981