Vincent Mailhol
f2c247e958
can: hi311x: populate ndo_change_mtu() to prevent buffer overflow
...
[ Upstream commit ac1c7656fa717f29fac3ea073af63f0b9919ec9a ]
Sending an PF_PACKET allows to bypass the CAN framework logic and to
directly reach the xmit() function of a CAN driver. The only check
which is performed by the PF_PACKET framework is to make sure that
skb->len fits the interface's MTU.
Unfortunately, because the sun4i_can driver does not populate its
net_device_ops->ndo_change_mtu(), it is possible for an attacker to
configure an invalid MTU by doing, for example:
$ ip link set can0 mtu 9999
After doing so, the attacker could open a PF_PACKET socket using the
ETH_P_CANXL protocol:
socket(PF_PACKET, SOCK_RAW, htons(ETH_P_CANXL))
to inject a malicious CAN XL frames. For example:
struct canxl_frame frame = {
.flags = 0xff,
.len = 2048,
};
The CAN drivers' xmit() function are calling can_dev_dropped_skb() to
check that the skb is valid, unfortunately under above conditions, the
malicious packet is able to go through can_dev_dropped_skb() checks:
1. the skb->protocol is set to ETH_P_CANXL which is valid (the
function does not check the actual device capabilities).
2. the length is a valid CAN XL length.
And so, hi3110_hard_start_xmit() receives a CAN XL frame which it is
not able to correctly handle and will thus misinterpret it as a CAN
frame. The driver will consume frame->len as-is with no further
checks.
This can result in a buffer overflow later on in hi3110_hw_tx() on
this line:
memcpy(buf + HI3110_FIFO_EXT_DATA_OFF,
frame->data, frame->len);
Here, frame->len corresponds to the flags field of the CAN XL frame.
In our previous example, we set canxl_frame->flags to 0xff. Because
the maximum expected length is 8, a buffer overflow of 247 bytes
occurs!
Populate net_device_ops->ndo_change_mtu() to ensure that the
interface's MTU can not be set to anything bigger than CAN_MTU. By
fixing the root cause, this prevents the buffer overflow.
Fixes: 57e83fb9b7 ("can: hi311x: Add Holt HI-311x CAN driver")
Signed-off-by: Vincent Mailhol <mailhol@kernel.org>
Link: https://patch.msgid.link/20250918-can-fix-mtu-v1-2-0d1cada9393b@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-10-02 13:34:33 +02:00
..
accessibility
acpi
ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value
2025-08-28 16:21:33 +02:00
amba
android
ata
ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig
2025-08-28 16:21:35 +02:00
atm
atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control().
2025-09-04 14:05:54 +02:00
auxdisplay
base
pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov
2025-08-28 16:21:34 +02:00
bcma
block
drbd: add missing kref_get in handle_write_conflicts
2025-08-28 16:21:24 +02:00
bluetooth
Bluetooth: btrtl: Prevent potential NULL dereference
2025-05-02 07:39:19 +02:00
bus
Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first"
2025-06-27 11:02:55 +01:00
cdrom
char
ipmi: Fix strcpy source and destination the same
2025-08-28 16:21:29 +02:00
clk
clk: sunxi-ng: v3s: Fix de clock definition
2025-08-28 16:21:20 +02:00
clocksource
clocksource/i8253: Use raw_spinlock_irqsave() in clockevent_i8253_disable()
2025-06-04 14:32:29 +02:00
connector
counter
cpufreq
cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table()
2025-08-28 16:21:30 +02:00
cpuidle
cpuidle: menu: Avoid discarding useful information
2025-06-04 14:32:32 +02:00
crypto
crypto: qat - fix seq_file position update in adf_ring_next()
2025-08-28 16:21:21 +02:00
dax
dca
devfreq
dio
dma
dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees
2025-10-02 13:34:29 +02:00
dma-buf
dma-buf: fix timeout handling in dma_resv_wait_timeout v2
2025-07-17 18:25:04 +02:00
edac
EDAC/altera: Delete an inappropriate dma_free_coherent() call
2025-10-02 13:34:27 +02:00
eisa
extcon
firewire
firmware
firmware: psci: Fix refcount leak in psci_dt_init
2025-06-27 11:02:46 +01:00
fpga
fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable()
2025-08-28 16:21:32 +02:00
fsi
gnss
gpio
gpio: pca953x: fix IRQ storm on system wake up
2025-09-09 18:44:00 +02:00
gpu
drm/amdgpu: drop hw access in non-DC audio fini
2025-09-09 18:43:59 +02:00
greybus
hid
HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version()
2025-09-04 14:05:56 +02:00
hsi
HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition
2025-05-02 07:39:18 +02:00
hv
hwmon
hwmon: (occ) fix unaligned accesses
2025-06-27 11:02:57 +01:00
hwspinlock
hwtracing
coresight: catu: Fix number of pages while using 64k pages
2025-04-10 14:29:41 +02:00
i2c
i2c: qup: jump out of the loop in case of timeout
2025-08-28 16:21:17 +02:00
i3c
i3c: don't fail if GETHDRCAP is unsupported
2025-08-28 16:21:29 +02:00
ide
idle
iio
iio: light: opt3001: fix deadlock due to concurrent flag access
2025-09-09 18:44:00 +02:00
infiniband
IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions
2025-10-02 13:34:33 +02:00
input
Input: xpad - set correct controller type for Acer NGR200
2025-08-28 16:21:14 +02:00
interconnect
iommu
iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid
2025-06-04 14:32:26 +02:00
ipack
irqchip
irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()
2025-06-04 14:32:25 +02:00
isdn
mISDN: Fix memory leak in dsp_hwec_enable()
2025-09-09 18:43:57 +02:00
leds
lightnvm
macintosh
mailbox
mailbox: Not protect module_put with spin_lock_irqsave
2025-07-17 18:24:49 +02:00
mcb
mcb: fix a double free bug in chameleon_parse_gdd()
2025-05-02 07:39:26 +02:00
md
md/raid1: Fix stack memory use after return in raid1_reshape
2025-07-17 18:25:04 +02:00
media
media: venus: hfi: explicitly release IRQ during teardown
2025-08-28 16:21:35 +02:00
memory
memstick
memstick: Fix deadlock by moving removing flag earlier
2025-08-28 16:21:32 +02:00
message
mfd
mfd: max14577: Fix wakeup source leaks on device unbind
2025-07-17 18:24:49 +02:00
misc
misc: rtsx: usb: Ensure mmc child device is active when card is present
2025-08-28 16:21:30 +02:00
mmc
mmc: mvsdio: Fix dma_unmap_sg() nents value
2025-10-02 13:34:31 +02:00
mtd
mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing
2025-10-02 13:34:28 +02:00
mux
net
can: hi311x: populate ndo_change_mtu() to prevent buffer overflow
2025-10-02 13:34:33 +02:00
nfc
ntb
ntb: reduce stack usage in idt_scan_mws
2025-05-02 07:39:28 +02:00
nubus
nvdimm
libnvdimm/labels: Fix divide error in nd_label_data_init()
2025-06-04 14:32:30 +02:00
nvme
nvmet-tcp: don't restore null sk_state_change
2025-06-04 14:32:35 +02:00
nvmem
of
of: module: add buffer overflow check in of_modalias()
2025-06-04 14:32:25 +02:00
opp
oprofile
parisc
parport
pci
PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports
2025-08-28 16:21:33 +02:00
pcmcia
pcmcia: omap_cf: Mark driver struct with __refdata to prevent section mismatch
2025-10-02 13:34:30 +02:00
perf
perf: arm_pmu: Don't disable counter in armpmu_add()
2025-05-02 07:39:09 +02:00
phy
phy: ti-pipe3: fix device leak at unbind
2025-10-02 13:34:30 +02:00
pinctrl
pinctrl: STMFX: add missing HAS_IOMEM dependency
2025-09-04 14:05:53 +02:00
platform
platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches
2025-08-28 16:21:25 +02:00
pnp
power
power: supply: bq27xxx: restrict no-battery detection to bq27000
2025-10-02 13:34:31 +02:00
powercap
pps
pps: fix poll support
2025-08-28 16:21:18 +02:00
ps3
ptp
pwm
pwm: mediatek: Fix duty and period setting
2025-08-28 16:21:35 +02:00
rapidio
drivers/rapidio/rio_cm.c: prevent possible heap overwrite
2025-06-27 11:02:56 +01:00
ras
regulator
regulator: core: fix NULL dereference on unbind due to stale coupling data
2025-08-28 16:21:17 +02:00
remoteproc
reset
rpmsg
rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send()
2025-06-27 11:02:48 +01:00
rtc
rtc: ds1307: handle oscillator stop flag (OSF) for ds1341
2025-08-28 16:21:35 +02:00
s390
scsi: s390: zfcp: Ensure synchronous unit_add
2025-06-27 11:02:56 +01:00
sbus
scsi
scsi: lpfc: Fix buffer free/clear order in deferred receive path
2025-09-09 18:43:59 +02:00
sfi
sh
siox
slimbus
soc
soc: qcom: mdt_loader: Deal with zero e_shentsize
2025-10-02 13:34:30 +02:00
soundwire
soundwire: stream: restore params when prepare ports fail
2025-08-28 16:21:21 +02:00
spi
spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort
2025-09-09 18:44:01 +02:00
spmi
ssb
staging
comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large
2025-08-28 16:21:33 +02:00
target
scsi: target: iscsi: Fix timeout on deleted connection
2025-06-04 14:32:29 +02:00
tc
tee
tee: Prevent size calculation wraparound on 32-bit kernels
2025-06-27 11:02:55 +01:00
thermal
thermal: sysfs: Return ENODATA instead of EAGAIN for reads
2025-08-28 16:21:25 +02:00
thunderbolt
thunderbolt: Fix copy+paste error in match_service_id()
2025-08-28 16:21:30 +02:00
tty
serial: sc16is7xx: fix bug in flow control levels init
2025-10-02 13:34:32 +02:00
uio
uio_hv_generic: Use correct size for interrupt and monitor pages
2025-06-27 11:02:52 +01:00
usb
usb: core: Add 0x prefix to quirks debug output
2025-10-02 13:34:33 +02:00
vfio
vhost
vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put()
2025-09-04 14:05:53 +02:00
video
Revert "vgacon: Add check for vc_origin address range in vgacon_scroll()"
2025-08-28 16:21:31 +02:00
virt
virtio
visorbus
vlynq
vme
w1
watchdog
watchdog: dw_wdt: Fix default timeout
2025-08-28 16:21:27 +02:00
xen
xen/swiotlb: relax alignment requirements
2025-06-04 14:32:37 +02:00
zorro
Kconfig
Makefile