SB20260325157 - Loop with Unreachable Exit Condition ('Infinite Loop') in Linux kernel can usb driver
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Loop with Unreachable Exit Condition ('Infinite Loop') (CVE-ID: CVE-2026-23298)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an infinite loop in the ucan driver when processing zero-length messages from a ucan device. A local user can connect a specially crafted ucan device to trigger an infinite loop in ucan_read_bulk_callback(), causing the system to hang.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/13b646eec3ba1131180803f5aaf1fee23540ad8f
- https://git.kernel.org/stable/c/1e446fd0582ad8be9f6dafb115fc2e7245f9bea7
- https://git.kernel.org/stable/c/aa9e0a7fe5efc2f74327fd37d828e9a51d9ff588
- https://git.kernel.org/stable/c/ab6f075492d37368b4c7b0df7f7fdc2b666887fc
- https://git.kernel.org/stable/c/bd85f21a6219aeae4389d700c54f1799f4b814e0
- https://git.kernel.org/stable/c/c7bc62be6c1a60bb21301692009590b1ffda91d9