CVE-2023-54039

Linux Kernel Out-of-Bounds Memory Access in j1939_tp_tx_dat_new()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_tp_tx_dat_new(): fix out-of-bounds memory access In the j1939_tp_tx_dat_new() function, an out-of-bounds memory access could occur during the memcpy() operation if the size of skb->cb is larger than the size of struct j1939_sk_buff_cb. This is because the memcpy() operation uses the size of skb->cb, leading to a read beyond the struct j1939_sk_buff_cb. Updated the memcpy() operation to use the size of struct j1939_sk_buff_cb instead of the size of skb->cb. This ensures that the memcpy() operation only reads the memory within the bounds of struct j1939_sk_buff_cb, preventing out-of-bounds memory access. Additionally, add a BUILD_BUG_ON() to check that the size of skb->cb is greater than or equal to the size of struct j1939_sk_buff_cb. This ensures that the skb->cb buffer is large enough to hold the j1939_sk_buff_cb structure. [mkl: rephrase commit message]

Scores

EPSS 0.0017
EPSS Percentile 6.4%

Details

Status published
Products (19)
linux/Kernel 5.11.0 - 5.15.107linux
linux/Kernel 5.16.0 - 6.1.24linux
linux/Kernel 5.4.0 - 5.4.241linux
linux/Kernel 5.5.0 - 5.10.178linux
linux/Kernel 6.2.0 - 6.2.11linux
Linux/Linux < 5.4
Linux/Linux 5.10.178 - 5.10.*
Linux/Linux 5.15.107 - 5.15.*
Linux/Linux 5.4
Linux/Linux 5.4.241 - 5.4.*
... and 9 more
Published Dec 24, 2025
Tracked Since Feb 18, 2026