High [CVE-2026-17523] can:bcm: arbitrary kernel code execution leading to escalate privileges
This high-severity Red Hat Linux advisory covers CVE-2026-17523 affecting Red Hat Enterprise Linux 8.8 Telecommunications Update Service, Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions, Red Hat package: kernel-rt.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vulnerability to execute arbitrary code within the kernel, which leads to a local privilege escalation (LPE). This allows the attacker to gain root privileges and take full control of the affected system.
This is an Important flaw in the Linux kernel's CAN BCM module that allows a local unprivileged attacker to achieve root privileges through arbitrary kernel code execution.
The vulnerability is present in Red Hat Enterprise Linux 8, where a proof of concept has demonstrated local privilege escalation, even without unprivileged user namespaces or the `kernel-modules-extra` package. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions.
Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9 as not affected. Red Hat fixing advisory: RHSA-2026:55765, RHSA-2026:55764, RHSA-2026:61932.
Affected products named by the advisory: Red Hat package: kernel-rt.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
- kernel-rt-0:4.18.0-553.156.1.rt7.497.el8_10
- kernel-0:4.18.0-553.156.1.el8_10
- kernel-0:4.18.0-477.163.1.el8_8
- RHSA-2026:55765
- RHSA-2026:55764
- RHSA-2026:61932
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
Mitigation checklist
- To mitigate this vulnerability, prevent the `bcm` kernel module from loading if it is not required. Create a file named `/etc/modprobe.d/blacklist-bcm.conf` with the content `blacklist bcm`. A system reboot is required for this change to take effect. This mitigation may impact functionality that relies on the CAN BCM module.
Official advisory · high-confidence parse· fetched 13 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.