CVE-2022-49659
MEDIUMLinux Kernel 5.13-5.15.54 5.16-5.18.11 - Integer Overflow in CAN RX-offload Timestamp Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_{read_fifo,echo_tx_event}(): shift timestamp to full 32 bits In commit 1be37d3b0414 ("can: m_can: fix periph RX path: use rx-offload to ensure skbs are sent from softirq context") the RX path for peripheral devices was switched to RX-offload. Received CAN frames are pushed to RX-offload together with a timestamp. RX-offload is designed to handle overflows of the timestamp correctly, if 32 bit timestamps are provided. The timestamps of m_can core are only 16 bits wide. So this patch shifts them to full 32 bit before passing them to RX-offload.
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0025
EPSS Percentile
16.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
Status
published
Products (12)
linux/Kernel
5.13.0 - 5.15.54linux
linux/Kernel
5.16.0 - 5.18.11linux
Linux/Linux
< 5.13
Linux/Linux
1be37d3b0414e3db47f6fcba6c16286bbae0cb65 - 2a2914a5bd7f38efe55a8372178146de82e0bce9
Linux/Linux
1be37d3b0414e3db47f6fcba6c16286bbae0cb65 - 4c3333693f07313f5f0145a922f14a7d3c0f4f21
Linux/Linux
1be37d3b0414e3db47f6fcba6c16286bbae0cb65 - c7333f79888497bfd75dcd02a94eaf836dd1042c
Linux/Linux
5.13
Linux/Linux
5.15.54 - 5.15.*
Linux/Linux
5.18.11 - 5.18.*
Linux/Linux
5.19
... and 2 more
Published
Feb 26, 2025
Tracked Since
Feb 18, 2026