can: isotp: fix potential CAN frame reception race in isotp_rcv()
Published Jul 16, 2024
8.8
HIGHCVSS 3.1
EPSS 0.31%
Description
When receiving a CAN frame the current code logic does not consider concurrently receiving processes which do not show up in real world usage.
Ziyang Xuan writes:
The following syz problem is one of the scenarios. so->rx.len is changed by isotp_rcv_ff() during isotp_rcv_cf(), so->rx.len equals 0 before alloc_skb() and equals 4096 after alloc_skb(). That will trigger skb_over_panic() in skb_put().
======================================================= CPU: 1 PID: 19 Comm: ksoftirqd/1 Not tainted 5.16.0-rc8-syzkaller #0 RIP: 0010:skb_panic+0x16c/0x16e net/core/skbuff.c:113 Call Trace: <TASK> skb_over_panic net/core/skbuff.c:118 [inline] skb_put.cold+0x24/0x24 net/core/skbuff.c:1990 isotp_rcv_cf net/can/isotp.c:570 [inline] isotp_rcv+0xa38/0x1e30 net/can/isotp.c:668 deliver net/can/af_can.c:574 [inline] can_rcv_filter+0x445/0x8d0 net/can/af_can.c:635 can_receive+0x31d/0x580 net/can/af_can.c:665 can_rcv+0x120/0x1c0 net/can/af_can.c:696 __netif_receive_skb_one_core+0x114/0x180 net/core/dev.c:5465 __netif_receive_skb+0x24/0x1b0 net/core/dev.c:5579
Therefore we make sure the state changes and data structures stay consistent at CAN frame reception time by adding a spin_lock in isotp_rcv(). This fixes the issue reported by syzkaller but does not affect real world operation.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.10
- Version 5.10.101StatusunaffectedConstraints<=5.10.*
- Version 5.15.24StatusunaffectedConstraints<=5.15.*
- Version 5.16.10StatusunaffectedConstraints<=5.16.*
- Version 5.17StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 5.10 · < 5.10.101
- ≥ 5.11 · < 5.15.24
- ≥ 5.16 · < 5.16.10
- 5.17
- 5.17
- 5.17
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.5.1.el9_7
Fixed · RHSA-2025:20518
Red Hat Enterprise Linux 9
kernel-0:5.14.0-611.5.1.el9_7
Fixed · RHSA-2025:20518
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.5.1.el9_7 | Fixed | RHSA-2025:20518 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-611.5.1.el9_7 | Fixed | RHSA-2025:20518 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-48830 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298169 Issue Tracking
- https://git.kernel.org/stable/c/5b068f33bc8acfcfd5ea7992a2dafb30d89bad30 Patch
- https://git.kernel.org/stable/c/7b53d2204ce79b27a878074a77d64f40ec21dbca Patch
- https://git.kernel.org/stable/c/7c759040c1dd03954f650f147ae7175476d51314 Patch
- https://git.kernel.org/stable/c/f90cc68f9f4b5d8585ad5d0a206a9d37ac299ef3 Patch
- https://lore.kernel.org/linux-cve-announce/2024071652-CVE-2022-48830-8dbf@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48830
- https://www.cve.org/CVERecord?id=CVE-2022-48830
Change history (0)
No recorded changes yet.