GHSA-35c8-wvgc-32mg · Severity: unknown — In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow...
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow partial RX URB allocation to succeed When es58x_alloc_rx_urbs() fails to allocate the requested number of URBs but succeeds in allocating some, it returns an error code. This causes es58x_open() to return early, skipping the cleanup label 'free_urbs', which leads to the anchored URBs being leaked. As pointed out by maintainer Vincent Mailhol, the driver is designed to handle partial URB allocation gracefully. Therefore, partial allocation should not be treated as a fatal error. Modify es58x_alloc_rx_urbs() to return 0 if at least one URB has been allocated, restoring the intended behavior and preventing the leak in es58x_open().
Conclusion & alert: CVE-2026-23037 is rated Low Risk (3.5/100): low exploitation likelihood (EPSS 0.02%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-31 | — | 0.02% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
No CVSS data in dataset for this CVE.
GHSA-35c8-wvgc-32mg · Severity: unknown — In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: allow...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2026-23037 unimportant priority: Debian including 2 source packages (linux, linux-6.1), 6 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 6. | https://security-tracker.debian.org/tracker/CVE-2026-23037 |
redhat
|
— | — | https://access.redhat.com/security/cve/CVE-2026-23037 |
suse
|
low | CVE-2026-23037 severity low: SUSE including 421 source package names (2.1.3-6.124:kernel-default-base-6.4.0-40.1.21.17, 2.1.3-7.105:kernel-default-6.4.0-40.1, …), 743 product×package rows across 60 product lines (Container suse/sl-micro/6.0/base-os-container, Container suse/sl-micro/6.0/kvm-os-container, … (60 product lines)): Fixed 308, Known Affected 231, Will Not Fix 109, Known Not Affected 70, First Fixed 25. | https://www.suse.com/security/cve/CVE-2026-23037/ |
ubuntu
|
medium | CVE-2026-23037 medium priority: Ubuntu including 157 source packages (linux, linux-allwinner-5.19, …), 1256 status rows across 8 suites (bionic, focal, jammy, noble, questing, trusty, upstream, xenial): DNE 871, ignored 169, released 102, needed 52, not-affected 46, pending 16. | https://ubuntu.com/security/CVE-2026-23037 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||