CVE-2022-49844

HIGH

Linux Kernel 6.0-6.0.8 - Out-of-bounds Read in CAN Interface Driver

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: can: dev: fix skb drop check In commit a6d190f8c767 ("can: skb: drop tx skb if in listen only mode") the priv->ctrlmode element is read even on virtual CAN interfaces that do not create the struct can_priv at startup. This out-of-bounds read may lead to CAN frame drops for virtual CAN interfaces like vcan and vxcan. This patch mainly reverts the original commit and adds a new helper for CAN interface drivers that provide the required information in struct can_priv. [mkl: patch pch_can, too]

Scores

CVSS v3 7.1
EPSS 0.0015
EPSS Percentile 4.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-125
Status published
Products (9)
linux/Kernel 6.0.0 - 6.0.9linux
Linux/Linux < 6.0
Linux/Linux 6.0
Linux/Linux 6.0.9 - 6.0.*
Linux/Linux 6.1
Linux/Linux a6d190f8c7670068d8c154ef8477eca07b5e3574 - 386c49fe31ee748e053860b3bac7794a933ac9ac
Linux/Linux a6d190f8c7670068d8c154ef8477eca07b5e3574 - ae64438be1923e3c1102d90fd41db7afcfaf54cc
linux/linux_kernel 6.1 rc1 (4 CPE variants)
linux/linux_kernel 6.0 - 6.0.9
Published May 01, 2025
Tracked Since Feb 18, 2026