CVE-2022-49844
HIGHLinux Kernel 6.0-6.0.8 - Out-of-bounds Read in CAN Interface Driver
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: can: dev: fix skb drop check In commit a6d190f8c767 ("can: skb: drop tx skb if in listen only mode") the priv->ctrlmode element is read even on virtual CAN interfaces that do not create the struct can_priv at startup. This out-of-bounds read may lead to CAN frame drops for virtual CAN interfaces like vcan and vxcan. This patch mainly reverts the original commit and adds a new helper for CAN interface drivers that provide the required information in struct can_priv. [mkl: patch pch_can, too]
References (2)
Core 2
Scores
CVSS v3
7.1
EPSS
0.0015
EPSS Percentile
4.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-125
Status
published
Products (9)
linux/Kernel
6.0.0 - 6.0.9linux
Linux/Linux
< 6.0
Linux/Linux
6.0
Linux/Linux
6.0.9 - 6.0.*
Linux/Linux
6.1
Linux/Linux
a6d190f8c7670068d8c154ef8477eca07b5e3574 - 386c49fe31ee748e053860b3bac7794a933ac9ac
Linux/Linux
a6d190f8c7670068d8c154ef8477eca07b5e3574 - ae64438be1923e3c1102d90fd41db7afcfaf54cc
linux/linux_kernel
6.1 rc1 (4 CPE variants)
linux/linux_kernel
6.0 - 6.0.9
Published
May 01, 2025
Tracked Since
Feb 18, 2026