Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
7.8
CVE-2026-17523EXPLOITEDPATCHED
red hat · red hat enterprise linux

Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges

Description

A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.

Affected Products

VendorProductVersions
red hatred hat enterprise linux—

References

  • https://access.redhat.com/errata/RHSA-2026:55764(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:55765(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-17523(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2507407(issue-tracking, x_refsource_REDHAT)
  • https://github.com/torvalds/linux/commit/bf74aa86e111aa3b2fbb25db37e3a3fab71b5b68

Related News (2 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans le noyau Linux de Red Hat (21 août 2026)
→ No new info (linked only)
Tier C
VulDB27d ago
CVE-2026-17523 | Linux Kernel privileges management
→ No new info (linked only)
CVSS 3.17.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
0:4.18.0-553.156.1.rt7.497.el8_10
CWECWE-825
PublishedJul 27, 2026
Last enriched27d ago
Tags
remote code executionfile manipulationdenial of servicemultiple vulnerabilities
Trending Score33
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-13595EXP
Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
Trending: 36
NONECVE-2026-18917EXP
Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow
Trending: 35
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 26
MEDIUMCVE-2026-73199EXP
Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value
Trending: 23
NONECVE-2026-77176
Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 27, 2026
Discovered by ZDM
Jul 27, 2026
Actively Exploited
Aug 17, 2026
Exploit Available
Aug 17, 2026
Patch Available
Aug 17, 2026