
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23334 is a buffer size miscalculation vulnerability in the Linux kernel's CAN USB driver (can: usb: f81604) that allows a local attacker to trigger a denial of service by sending malformed interrupt USB request blocks (URBs). The flaw was published on March 25, 2026, and affects Linux kernel versions from 6.5 through multiple stable branches, including 6.5.1–6.6.130, 6.7–6.12.77, 6.13–6.18.17, 6.19–6.19.7, and pre-release 7.0-rc1 through 7.0-rc7. Microsoft Azure Linux 3 kernel version 6.6.126.1-1 and earlier is also affected. It carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Microsoft MSRC).
The root cause is classified as CWE-131 (Incorrect Calculation of Buffer Size). The f81604 CAN USB driver fails to validate the length of received interrupt URB messages; when a short or malformed URB arrives, the driver does not detect the size mismatch and proceeds to process the data as if it were valid, leading to improper buffer size calculations and potential memory corruption. Exploitation requires local access with low privileges and physical or logical ability to present a malicious USB CAN device to the system — no user interaction is needed once the device is connected. Patches are available across multiple stable kernel trees via the upstream kernel git repository (Red Hat CVE, Feedly).
Successful exploitation primarily affects system availability: a local attacker with low privileges can cause kernel crashes or unexpected system behavior by submitting malformed interrupt URBs through a connected CAN USB device. There is no direct confidentiality or integrity impact (CVSS C:N/I:N/A:H). The scope is limited to the affected host, with no evidence of lateral movement potential, though a system crash could disrupt industrial or embedded environments relying on CAN bus communication (Red Hat CVE, Microsoft MSRC).
Apply the available kernel patches to upgrade to a fixed version: 6.6.130 or later, 6.12.77 or later, 6.18.17 or later, 6.19.7 or later, or 7.0-rc3 or later. Microsoft Azure Linux 3 users should apply the updated kernel package addressing this issue. As interim mitigations, restrict physical USB port access to trusted users, disable CAN USB support (f81604 module) on systems that do not require it via kernel module blacklisting, and monitor for unexpected kernel crashes related to CAN USB device handling (Red Hat CVE, Microsoft MSRC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."