CVE-2026-23307Disclosure(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message When looking at the data in a USB urb, the actual_length is the size of the buffer passed to the driver, not the transfer_buffer_length which is set by the driver as the max size of the buffer. When parsing the messages in ems_usb_read_bulk_callback() properly check the size both at the beginning of parsing the message to make sure it is big enough for the expected structure, and at the end of the message to make sure we don't overflow past the end of the buffer for the next message.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 203-2503-28
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure1Patch1
2026-03-281
General1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-23307 In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message When looking at… https://www.cve.org/CVERecord?id=CVE-2026-23307

    Post summary

    CVE-2026-23307 is a length-check issue in the Linux kernel's ems_usb driver that has been fixed; a patch is available and no active exploitation or PoC is reported.

    00010178
    56.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23307 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23307 #CVE-2026-23307 #CVE   #CyberSecurity #InfoSec https://t.co/DbRPNUtNcK

    Post summary

    The tweet announces CVE-2026-23307 but provides no technical details, exploits, or mitigation information.

    0000026
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23307 In the Linux kernel, the following vulnerability has been resolved: can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message When looking at… https://www.cve.org/CVERecord?id=CVE-2026-23307 ----- Traducción: CVE-2026-23307 En … http://infoflow.cloud`

    Post summary

    The text announces that CVE-2026-23307 in the Linux kernel has been resolved, providing a link to the CVE record but no further technical or exploit details.

    0000027
    61 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more