5.5

CVE-2022-48977

can: af_can: fix NULL pointer dereference in can_rcv_filter

In the Linux kernel, the following vulnerability has been resolved:

can: af_can: fix NULL pointer dereference in can_rcv_filter

Analogue to commit 8aa59e355949 ("can: af_can: fix NULL pointer
dereference in can_rx_register()") we need to check for a missing
initialization of ml_priv in the receive path of CAN frames.

Since commit 4e096a18867a ("net: introduce CAN specific pointer in the
struct net_device") the check for dev->type to be ARPHRD_CAN is not
sufficient anymore since bonding or tun netdevices claim to be CAN
devices but do not initialize ml_priv accordingly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.4.110 < 5.4.227
Linux ≫ Linux Kernel Version >= 5.10.28 < 5.10.159
Linux ≫ Linux Kernel Version >= 5.11.12 < 5.15.83
Linux ≫ Linux Kernel Version >= 5.16 < 6.0.13
Linux ≫ Linux Kernel Version 6.1 Update rc1
Linux ≫ Linux Kernel Version 6.1 Update rc2
Linux ≫ Linux Kernel Version 6.1 Update rc3
Linux ≫ Linux Kernel Version 6.1 Update rc4
Linux ≫ Linux Kernel Version 6.1 Update rc5
Linux ≫ Linux Kernel Version 6.1 Update rc6
Linux ≫ Linux Kernel Version 6.1 Update rc7
Linux ≫ Linux Kernel Version 6.1 Update rc8
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.159
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/0acc442309a0a1b01bcdaa135e56e6398a49439c
Patch
https://git.kernel.org/stable/c/3982652957e8d79ac32efcb725450580650a8644
Patch
https://git.kernel.org/stable/c/c142cba37de29f740a3852f01f59876af8ae462a
Patch
https://git.kernel.org/stable/c/c42221efb1159d6a3c89e96685ee38acdce86b6f
Patch
https://git.kernel.org/stable/c/fcc63f2f7ee3038d53216edd0d8291e57c752557
Patch