CVE-2022-49844

HIGH

Linux Kernel < 6.0.9 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: can: dev: fix skb drop check In commit a6d190f8c767 ("can: skb: drop tx skb if in listen only mode") the priv->ctrlmode element is read even on virtual CAN interfaces that do not create the struct can_priv at startup. This out-of-bounds read may lead to CAN frame drops for virtual CAN interfaces like vcan and vxcan. This patch mainly reverts the original commit and adds a new helper for CAN interface drivers that provide the required information in struct can_priv. [mkl: patch pch_can, too]

Scores

CVSS v3 7.1
EPSS 0.0008
EPSS Percentile 22.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-125
Status published
Products (3)
linux/Kernel 6.0.0 - 6.0.9linux
linux/linux_kernel 6.1 rc1 (4 CPE variants)
linux/linux_kernel 6.0 - 6.0.9
Published May 01, 2025
Tracked Since Feb 18, 2026