In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: validate uCAN receive record lengths pcan_usb_fd_decode_buf() walks uCAN records packed in one USB receive buffer.…
Info
Summary
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: validate uCAN receive record lengths pcan_usb_fd_decode_buf() walks uCAN records packed in one USB receive buffer. Require each record to contain the fixed header for its type, and verify CAN payload bytes before copying them into the skb.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/2427ef427bdd78d862c7c76597bfd9eda88b81f1
- https://git.kernel.org/stable/c/2c8f08f3641a074da40acf05baa5a18ae2739260
- https://git.kernel.org/stable/c/6067c878e38d02a3d5c43497347e143f85c9064a
- https://git.kernel.org/stable/c/93fcab2c6968446316bbb49548848df604d6346f
- https://git.kernel.org/stable/c/d9c115948c3dd5fcc2d0245cec5eb76c098503c8
Timeline
- nvd_ingest NVD