HarborGuard / CVE
Back to search
HIGHCVE-2026-22997Published Modified CNA Linux

CVE-2026-22997: net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts

In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts Since j1939_session_deactivate_activate_next() in j1939_tp_rxtimer() is called only when the timer is enabled, we need to call j1939_session_deactivate_activate_next() if we cancelled the timer. Otherwise, refcount for j1939_session leaks, which will later appear as | unregister_netdevice: waiting for vcan0 to become free. Usage count = 2. problem.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
0
Affected Products
2

Fix available

01809c82aa073a11b7d335ae932d81ce51a588a4a5.10.2495.15.1996.1.1626.6.1226.12.676.18.76.196121b7564c725b632ffe4764abe85aa239d37703809a437e27a3bf3c1c6c8c157773635552116f2ba73e7d7e346dae1c22dc3e95b02ca464b12daf2cadabf01c19561e42899da9de56a6a1da0e6b8a5bb1d67607e97d489c0cfbbf55f48a76b00710b0e4cb2a610867bc379988bae0bb4b8bbc59c0decf1a
Affected packages
  • Linux / Linux
    < a73e7d7e346dae1c22dc3e95b02ca464b12daf2c (from 9d71dd0c70099914fcd063135da3c580865e924c) · < adabf01c19561e42899da9de56a6a1da0e6b8a5b (from 9d71dd0c70099914fcd063135da3c580865e924c) · < b1d67607e97d489c0cfbbf55f48a76b00710b0e4 (from 9d71dd0c70099914fcd063135da3c580865e924c) · < 809a437e27a3bf3c1c6c8c157773635552116f2b (from 9d71dd0c70099914fcd063135da3c580865e924c) · < cb2a610867bc379988bae0bb4b8bbc59c0decf1a (from 9d71dd0c70099914fcd063135da3c580865e924c) · < 6121b7564c725b632ffe4764abe85aa239d37703 (from 9d71dd0c70099914fcd063135da3c580865e924c)
  • Linux / Linux
    5.4
    Fixed in 0, 5.10.249, 5.15.199, 6.1.162, 6.6.122, 6.12.67, 6.18.7, 6.19
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-22997: net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts | HarborGuard CVE