Back

CRITICAL

can: j1939: fix Use-after-Free, hold skb ref while in use

Published May 21, 2024

Description

This patch fixes a Use-after-Free found by the syzbot.

The problem is that a skb is taken from the per-session skb queue, without incrementing the ref count. This leads to a Use-after-Free if the skb is taken concurrently from the session queue due to a CTS.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published May 21, 2024
Updated Aug 5, 2026
Reserved Apr 10, 2024
CISA Vulnrichment
Updated May 28, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Low
Public date May 21, 2024