CVE-2026-23334
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-23334 is a buffer size miscalculation vulnerability in the Linux kernel's CAN USB driver (can: usb: f81604) that allows a local attacker to trigger a denial of service by sending malformed interrupt USB request blocks (URBs). The flaw was published on March 25, 2026, and affects Linux kernel versions from 6.5 through multiple stable branches, including 6.5.1–6.6.130, 6.7–6.12.77, 6.13–6.18.17, 6.19–6.19.7, and pre-release 7.0-rc1 through 7.0-rc7. Microsoft Azure Linux 3 kernel version 6.6.126.1-1 and earlier is also affected. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Microsoft MSRC).

Technical details

The root cause is classified as CWE-131 (Incorrect Calculation of Buffer Size). The f81604 CAN USB driver fails to validate the length of received interrupt URB messages; when a short or malformed URB arrives, the driver does not detect the size mismatch and proceeds to process the data as if it were valid, leading to improper buffer size calculations and potential memory corruption. Exploitation requires local access with low privileges and physical or logical ability to present a malicious USB CAN device to the system — no user interaction is needed once the device is connected. Patches are available across multiple stable kernel trees via the upstream kernel git repository (Red Hat CVE, Feedly).

Impact

Successful exploitation primarily affects system availability: a local attacker with low privileges can cause kernel crashes or unexpected system behavior by submitting malformed interrupt URBs through a connected CAN USB device. There is no direct confidentiality or integrity impact (CVSS C:N/I:N/A:H). The scope is limited to the affected host, with no evidence of lateral movement potential, though a system crash could disrupt industrial or embedded environments relying on CAN bus communication (Red Hat CVE, Microsoft MSRC).

Mitigation and workarounds

Apply the available kernel patches to upgrade to a fixed version: 6.6.130 or later, 6.12.77 or later, 6.18.17 or later, 6.19.7 or later, or 7.0-rc3 or later. Microsoft Azure Linux 3 users should apply the updated kernel package addressing this issue. As interim mitigations, restrict physical USB port access to trusted users, disable CAN USB support (f81604 module) on systems that do not require it via kernel module blacklisting, and monitor for unexpected kernel crashes related to CAN USB device handling (Red Hat CVE, Microsoft MSRC).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64530CRITICAL9.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-uki-virt-addons
NoYesJul 26, 2026
CVE-2026-64515HIGH8.3
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg
NoYesJul 25, 2026
CVE-2026-17523HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules-internal
NoNoJul 27, 2026
CVE-2024-14040HIGH7.8
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesJul 26, 2026
CVE-2026-64535NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management