can: af_can: fix NULL pointer dereference in can_rcv_filter
Published Oct 21, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
Analogue to commit 8aa59e355949 ("can: af_can: fix NULL pointer dereference in can_rx_register()") we need to check for a missing initialization of ml_priv in the receive path of CAN frames.
Since commit 4e096a18867a ("net: introduce CAN specific pointer in the struct net_device") the check for dev->type to be ARPHRD_CAN is not sufficient anymore since bonding or tun netdevices claim to be CAN devices but do not initialize ml_priv accordingly.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version
-
- Version 5.10.28StatusaffectedConstraints<5.10.159
- Version 5.11.12StatusaffectedConstraints<5.12
- Version 5.4.110StatusaffectedConstraints<5.4.227
- Version
-
- Version 5.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.12
- Version 5.10.159StatusunaffectedConstraints<=5.10.*
- Version 5.15.83StatusunaffectedConstraints<=5.15.*
- Version 5.4.227StatusunaffectedConstraints<=5.4.*
- Version 6.0.13StatusunaffectedConstraints<=6.0.*
- Version 6.1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.4.110 · < 5.4.227
- ≥ 5.10.28 · < 5.10.159
- ≥ 5.11.12 · < 5.15.83
- ≥ 5.16 · < 6.0.13
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
- 6.1
No data.
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-48977 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320678 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53856 Advisory
- https://git.kernel.org/stable/c/0acc442309a0a1b01bcdaa135e56e6398a49439c Patch
- https://git.kernel.org/stable/c/3982652957e8d79ac32efcb725450580650a8644 Patch
- https://git.kernel.org/stable/c/c142cba37de29f740a3852f01f59876af8ae462a Patch
- https://git.kernel.org/stable/c/c42221efb1159d6a3c89e96685ee38acdce86b6f Patch
- https://git.kernel.org/stable/c/fcc63f2f7ee3038d53216edd0d8291e57c752557 Patch
- https://lore.kernel.org/linux-cve-announce/2024102145-CVE-2022-48977-0990@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48977
- https://www.cve.org/CVERecord?id=CVE-2022-48977
Change history (0)
No recorded changes yet.