{"api_version":"1","generated_at":"2026-08-20T17:59:23+00:00","cve":"CVE-2026-72123","urls":{"html":"https://cve.report/CVE-2026-72123","api":"https://cve.report/api/cve/CVE-2026-72123.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72123","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72123"},"summary":{"title":"can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF\n\nCommit f1b4e32aca08 (\"can: bcm: use call_rcu() instead of costly\nsynchronize_rcu()\") replaced synchronize_rcu() in bcm_delete_rx_op()\nwith call_rcu() and introduced the RX_NO_AUTOTIMER flag.\n\nHowever, this flag check was omitted for thrtimer in the packet rx\nfast-path. During BCM RX operation teardown, a concurrent RCU reader\n(bcm_rx_handler) can race and re-arm thrtimer via\nbcm_rx_update_and_send() after call_rcu() has been scheduled.  Once\nthe RCU grace period elapses, bcm_op is freed.  The subsequently\nfiring thrtimer then dereferences the deallocated op, causing a UAF.\n\nAdding flag checks to the rx fast-path (bcm_rx_update_and_send) does not\nfully close the TOCTOU race and introduces latency for every CAN frame.\nConversely, calling hrtimer_cancel() directly inside the RCU callback\n(softirq context) is fatal as hrtimer_cancel() can sleep, triggering\na \"scheduling while atomic\" panic.\n\nResolve this by deferring the timer cancellation and memory free to a\ndedicated unbound workqueue (bcm_wq).  The RCU callback now queues a\nwork item to bcm_wq, which safely cancels both timers and deallocates\nmemory in sleepable process context.  A dedicated workqueue is used to\nprevent system-wide WQ saturation and is cleanly flushed/destroyed\non module unload to avoid rmmod page faults.\n\nSince the deferred work can now outlive the calling context by an\nunbounded amount, also take a reference on op->sk when it is assigned\nand drop it only once the deferred work has cancelled both timers, so a\nsocket can no longer be freed out from under a still-armed timer whose\ncallback (bcm_send_to_user()) dereferences op->sk.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:21:29","updated_at":"2026-08-19 17:20:59"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5","name":"https://git.kernel.org/stable/c/cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/036a8c320ca11bc912e8027adcfad14b326f067e","name":"https://git.kernel.org/stable/c/036a8c320ca11bc912e8027adcfad14b326f067e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/68973f9db76144825e4f35dfdc80fb8279eb2d57","name":"https://git.kernel.org/stable/c/68973f9db76144825e4f35dfdc80fb8279eb2d57","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/de5fce46637de05bef56ec08528127676eb6fc9b","name":"https://git.kernel.org/stable/c/de5fce46637de05bef56ec08528127676eb6fc9b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3cf4fd5316f449811d8baf1bc6978ef5a7b743a9","name":"https://git.kernel.org/stable/c/3cf4fd5316f449811d8baf1bc6978ef5a7b743a9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f","name":"https://git.kernel.org/stable/c/6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ce2d4b121fb7545e1ed588e860c8e5fd5ad45224","name":"https://git.kernel.org/stable/c/ce2d4b121fb7545e1ed588e860c8e5fd5ad45224","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4177762f70646ac48a2af382e45a795cbd295198","name":"https://git.kernel.org/stable/c/4177762f70646ac48a2af382e45a795cbd295198","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72123","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72123","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 85cd41070df992d3c0dfd828866fdd243d3b774a de5fce46637de05bef56ec08528127676eb6fc9b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f34f2a18e47b73e48f90a757e1f4aaa8c7d665a1 036a8c320ca11bc912e8027adcfad14b326f067e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f1b4e32aca0811aa011c76e5d6cf2fa19224b386 3cf4fd5316f449811d8baf1bc6978ef5a7b743a9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f1b4e32aca0811aa011c76e5d6cf2fa19224b386 4177762f70646ac48a2af382e45a795cbd295198 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f1b4e32aca0811aa011c76e5d6cf2fa19224b386 6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f1b4e32aca0811aa011c76e5d6cf2fa19224b386 cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f1b4e32aca0811aa011c76e5d6cf2fa19224b386 ce2d4b121fb7545e1ed588e860c8e5fd5ad45224 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f1b4e32aca0811aa011c76e5d6cf2fa19224b386 68973f9db76144825e4f35dfdc80fb8279eb2d57 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fbac09a3b8890003c0c55294c00709f3ae5501bb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5b48f5711f1c630841ab78dcc061de902f0e37bf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected edb4baffb9483141a50fb7f7146cfe4a4c0c2db8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10.130 5.10.265 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15.54 5.15.216 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19.252 4.20 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.205 5.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.18.11 5.19 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.19","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.19 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.265 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.216 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72123","cve":"CVE-2026-72123","epss":"0.001640000","percentile":"0.061170000","score_date":"2026-08-19","updated_at":"2026-08-20 00:13:09"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"de5fce46637de05bef56ec08528127676eb6fc9b","status":"affected","version":"85cd41070df992d3c0dfd828866fdd243d3b774a","versionType":"git"},{"lessThan":"036a8c320ca11bc912e8027adcfad14b326f067e","status":"affected","version":"f34f2a18e47b73e48f90a757e1f4aaa8c7d665a1","versionType":"git"},{"lessThan":"3cf4fd5316f449811d8baf1bc6978ef5a7b743a9","status":"affected","version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","versionType":"git"},{"lessThan":"4177762f70646ac48a2af382e45a795cbd295198","status":"affected","version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","versionType":"git"},{"lessThan":"6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f","status":"affected","version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","versionType":"git"},{"lessThan":"cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5","status":"affected","version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","versionType":"git"},{"lessThan":"ce2d4b121fb7545e1ed588e860c8e5fd5ad45224","status":"affected","version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","versionType":"git"},{"lessThan":"68973f9db76144825e4f35dfdc80fb8279eb2d57","status":"affected","version":"f1b4e32aca0811aa011c76e5d6cf2fa19224b386","versionType":"git"},{"status":"affected","version":"fbac09a3b8890003c0c55294c00709f3ae5501bb","versionType":"git"},{"status":"affected","version":"5b48f5711f1c630841ab78dcc061de902f0e37bf","versionType":"git"},{"status":"affected","version":"edb4baffb9483141a50fb7f7146cfe4a4c0c2db8","versionType":"git"},{"lessThan":"5.10.265","status":"affected","version":"5.10.130","versionType":"semver"},{"lessThan":"5.15.216","status":"affected","version":"5.15.54","versionType":"semver"},{"lessThan":"4.20","status":"affected","version":"4.19.252","versionType":"semver"},{"lessThan":"5.5","status":"affected","version":"5.4.205","versionType":"semver"},{"lessThan":"5.19","status":"affected","version":"5.18.11","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/can/bcm.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.19"},{"lessThan":"5.19","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.265","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.216","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.265","versionStartIncluding":"5.10.130","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.216","versionStartIncluding":"5.15.54","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"5.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"5.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"5.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"5.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"5.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.252","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.205","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.18.11","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF\n\nCommit f1b4e32aca08 (\"can: bcm: use call_rcu() instead of costly\nsynchronize_rcu()\") replaced synchronize_rcu() in bcm_delete_rx_op()\nwith call_rcu() and introduced the RX_NO_AUTOTIMER flag.\n\nHowever, this flag check was omitted for thrtimer in the packet rx\nfast-path. During BCM RX operation teardown, a concurrent RCU reader\n(bcm_rx_handler) can race and re-arm thrtimer via\nbcm_rx_update_and_send() after call_rcu() has been scheduled.  Once\nthe RCU grace period elapses, bcm_op is freed.  The subsequently\nfiring thrtimer then dereferences the deallocated op, causing a UAF.\n\nAdding flag checks to the rx fast-path (bcm_rx_update_and_send) does not\nfully close the TOCTOU race and introduces latency for every CAN frame.\nConversely, calling hrtimer_cancel() directly inside the RCU callback\n(softirq context) is fatal as hrtimer_cancel() can sleep, triggering\na \"scheduling while atomic\" panic.\n\nResolve this by deferring the timer cancellation and memory free to a\ndedicated unbound workqueue (bcm_wq).  The RCU callback now queues a\nwork item to bcm_wq, which safely cancels both timers and deallocates\nmemory in sleepable process context.  A dedicated workqueue is used to\nprevent system-wide WQ saturation and is cleanly flushed/destroyed\non module unload to avoid rmmod page faults.\n\nSince the deferred work can now outlive the calling context by an\nunbounded amount, also take a reference on op->sk when it is assigned\nand drop it only once the deferred work has cancelled both timers, so a\nsocket can no longer be freed out from under a still-armed timer whose\ncallback (bcm_send_to_user()) dereferences op->sk."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local BCM socket syscalls (sendmsg with RX_SETUP/SETTIMER/ival2 throttling and RX_DELETE); CAN frames can be injected locally via loopback without physical bus access.\nAC:L - The attacker controls both sides of the race by concurrently issuing RX_DELETE teardown and delivering matching CAN frames (e.g., via threads or paired BCM/RAW sockets), making the thrtimer re-arm UAF reliably triggerable.\nPR:L - No kernel capability check gates AF_CAN/CAN_BCM socket creation or bcm_sendmsg opcodes; any unprivileged local user with socket access (including via user namespaces with vcan) can reach the vulnerable path.\nUI:N - No victim interaction is required; the attacker self-triggers the race through their own BCM socket operations and locally injected CAN traffic.\nS:U - Impact is confined to kernel memory corruption and local privilege escalation within the same kernel security boundary, not a cross-boundary escape such as VM or IOMMU bypass.\nC:H - The thrtimer UAF dereferences freed bcm_op fields (locks, frame buffers, op->sk) in bcm_rx_thr_handler/bcm_send_to_user, enabling attacker-controlled heap reuse and arbitrary kernel memory disclosure.\nI:H - UAF on the bcm_op slab object allows heap spraying to corrupt function pointers, timers, and sock structures, providing a standard path to arbitrary kernel writes and local privilege escalation.\nA:H - The freed-op dereference in the hrtimer softirq path causes kernel oops/panic under normal exploitation attempts, and successful memory corruption can crash or hang the system."}]}],"providerMetadata":{"dateUpdated":"2026-08-19T16:36:18.988Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/de5fce46637de05bef56ec08528127676eb6fc9b"},{"url":"https://git.kernel.org/stable/c/036a8c320ca11bc912e8027adcfad14b326f067e"},{"url":"https://git.kernel.org/stable/c/3cf4fd5316f449811d8baf1bc6978ef5a7b743a9"},{"url":"https://git.kernel.org/stable/c/4177762f70646ac48a2af382e45a795cbd295198"},{"url":"https://git.kernel.org/stable/c/6fd08e8d826c3aa4cc7021f5f9cdbb7fa7441d3f"},{"url":"https://git.kernel.org/stable/c/cd830e0bc25ee2d38cbfbdbb3cd77c5f53b2b6d5"},{"url":"https://git.kernel.org/stable/c/ce2d4b121fb7545e1ed588e860c8e5fd5ad45224"},{"url":"https://git.kernel.org/stable/c/68973f9db76144825e4f35dfdc80fb8279eb2d57"}],"title":"can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72123","datePublished":"2026-08-15T05:53:01.433Z","dateReserved":"2026-08-09T03:40:39.907Z","dateUpdated":"2026-08-19T16:36:18.988Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:21:29","lastModifiedDate":"2026-08-19 17:20:59","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72123","Ordinal":"1","Title":"can: bcm: defer rx_op deallocation to workqueue to fix thrtimer ","CVE":"CVE-2026-72123","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72123","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF\n\nCommit f1b4e32aca08 (\"can: bcm: use call_rcu() instead of costly\nsynchronize_rcu()\") replaced synchronize_rcu() in bcm_delete_rx_op()\nwith call_rcu() and introduced the RX_NO_AUTOTIMER flag.\n\nHowever, this flag check was omitted for thrtimer in the packet rx\nfast-path. During BCM RX operation teardown, a concurrent RCU reader\n(bcm_rx_handler) can race and re-arm thrtimer via\nbcm_rx_update_and_send() after call_rcu() has been scheduled.  Once\nthe RCU grace period elapses, bcm_op is freed.  The subsequently\nfiring thrtimer then dereferences the deallocated op, causing a UAF.\n\nAdding flag checks to the rx fast-path (bcm_rx_update_and_send) does not\nfully close the TOCTOU race and introduces latency for every CAN frame.\nConversely, calling hrtimer_cancel() directly inside the RCU callback\n(softirq context) is fatal as hrtimer_cancel() can sleep, triggering\na \"scheduling while atomic\" panic.\n\nResolve this by deferring the timer cancellation and memory free to a\ndedicated unbound workqueue (bcm_wq).  The RCU callback now queues a\nwork item to bcm_wq, which safely cancels both timers and deallocates\nmemory in sleepable process context.  A dedicated workqueue is used to\nprevent system-wide WQ saturation and is cleanly flushed/destroyed\non module unload to avoid rmmod page faults.\n\nSince the deferred work can now outlive the calling context by an\nunbounded amount, also take a reference on op->sk when it is assigned\nand drop it only once the deferred work has cancelled both timers, so a\nsocket can no longer be freed out from under a still-armed timer whose\ncallback (bcm_send_to_user()) dereferences op->sk.","Type":"Description","Title":"can: bcm: defer rx_op deallocation to workqueue to fix thrtimer "}]}}}