-
CVE-2026-23298
- EPSS 0.04%
- Veröffentlicht 25.03.2026 10:26:54
- Zuletzt bearbeitet 18.04.2026 09:16:17
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
can: ucan: Fix infinite loop from zero-length messages
In the Linux kernel, the following vulnerability has been resolved:
can: ucan: Fix infinite loop from zero-length messages
If a broken ucan device gets a message with the message length field set
to 0, then the driver will loop for forever in
ucan_read_bulk_callback(), hanging the system. If the length is 0, just
skip the message and go on to the next one.
This has been fixed in the kvaser_usb driver in the past in commit
0c73772cd2b8 ("can: kvaser_usb: leaf: Fix potential infinite loop in
command parsers"), so there must be some broken devices out there like
this somewhere.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
9f2d3eae88d26c29d96e42983b755940d9169cd9
Version <
ca07d3c6eef14d34e6fdeefe55058db045be29dc
Status
affected
Version
9f2d3eae88d26c29d96e42983b755940d9169cd9
Version <
e7bb6e0606b5f233531aaaad9542d69fbb792115
Status
affected
Version
9f2d3eae88d26c29d96e42983b755940d9169cd9
Version <
ab6f075492d37368b4c7b0df7f7fdc2b666887fc
Status
affected
Version
9f2d3eae88d26c29d96e42983b755940d9169cd9
Version <
13b646eec3ba1131180803f5aaf1fee23540ad8f
Status
affected
Version
9f2d3eae88d26c29d96e42983b755940d9169cd9
Version <
bd85f21a6219aeae4389d700c54f1799f4b814e0
Status
affected
Version
9f2d3eae88d26c29d96e42983b755940d9169cd9
Version <
aa9e0a7fe5efc2f74327fd37d828e9a51d9ff588
Status
affected
Version
9f2d3eae88d26c29d96e42983b755940d9169cd9
Version <
c7bc62be6c1a60bb21301692009590b1ffda91d9
Status
affected
Version
9f2d3eae88d26c29d96e42983b755940d9169cd9
Version <
1e446fd0582ad8be9f6dafb115fc2e7245f9bea7
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.19
Status
affected
Version
0
Version <
4.19
Status
unaffected
Version <=
5.10.*
Version
5.10.253
Status
unaffected
Version <=
5.15.*
Version
5.15.203
Status
unaffected
Version <=
6.1.*
Version
6.1.167
Status
unaffected
Version <=
6.6.*
Version
6.6.130
Status
unaffected
Version <=
6.12.*
Version
6.12.77
Status
unaffected
Version <=
6.18.*
Version
6.18.17
Status
unaffected
Version <=
6.19.*
Version
6.19.7
Status
unaffected
Version <=
*
Version
7.0
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.102 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|