Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-46103— can: ucan: fix devres lifetime

AI Predicted 3.3 Difficulty: Trivial

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinux9f2d3eae88d26c29d96e42983b755940d9169cd9< 4b7d07747400cfd7eff1ba7b8b5a7c8d5a58f705affected
9f2d3eae88d26c29d96e42983b755940d9169cd9< 10b7b676b78a7bd888d19729b459aad7fc1f428baffected
9f2d3eae88d26c29d96e42983b755940d9169cd9< c524c124e3094d2de12235a513854c03d06a2b58affected
9f2d3eae88d26c29d96e42983b755940d9169cd9< c0d3ccc6929e4509076df8f30a4fb1dc5018b0aeaffected
9f2d3eae88d26c29d96e42983b755940d9169cd9< fed4626501c871890da287bec62a96e52da1af89affected
4.19affected
< 4.19unaffected
6.6.140≤ 6.6.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46103

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
can: ucan: fix devres lifetime
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix devres lifetime USB drivers bind to USB interfaces and any device managed resources should have their lifetime tied to the interface rather than parent USB device. This avoids issues like memory leaks when drivers are unbound without their devices being physically disconnected (e.g. on probe deferral or configuration changes). Fix the control message buffer lifetime so that it is released on driver unbind.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 9f2d3eae88d26c29d96e42983b755940d9169cd9 ~ 4b7d07747400cfd7eff1ba7b8b5a7c8d5a58f705 -
LinuxLinux 4.19 -

II. Public POCs for CVE-2026-46103

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46103

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46103 (5)

Same Patch Batch · Linux · 2026-05-27 · 276 CVEs total

CVE-2026-45915fat: avoid parent link count underflow in rmdir
CVE-2026-45932bpf: Fix tcx/netkit detach permissions when prog fd isn't given
CVE-2026-45931accel/amdxdna: Hold mm structure across iommu_sva_unbind_device()
CVE-2026-45930net: mctp: ensure our nlmsg responses are initialised
CVE-2026-45929ovpn: fix possible use-after-free in ovpn_net_xmit
CVE-2026-45928media: chips-media: wave5: Fix memory leak on codec_info allocation failure
CVE-2026-45927bpf: Require frozen map for calculating map hash
CVE-2026-45926rust: pwm: Fix potential memory leak on init error
CVE-2026-45925thermal/of: Fix reference leak in thermal_of_cm_lookup()
CVE-2026-45924ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths
CVE-2026-45923net: usb: catc: enable basic endpoint checking
CVE-2026-45922RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler
CVE-2026-45921mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse()
CVE-2026-45920ext4: fix dirtyclusters double decrement on fs shutdown
CVE-2026-45919sched/rt: Skip currently executing CPU in rto_next_cpu()
CVE-2026-45918ovpn: tcp - don't deref NULL sk_socket member after tcp_close()
CVE-2026-45917ipvs: do not keep dest_dst if dev is going down
CVE-2026-45916power: supply: sbs-battery: Fix use-after-free in power_supply_changed()
CVE-2026-45905xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path
CVE-2026-45903bpf: Fix memory access flags in helper prototypes

Showing top 20 of 276 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-46103

No comments yet


Leave a comment