android_kernel_motorola_sm6375/drivers
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Vincent Mailhol f2c247e958 can: hi311x: populate ndo_change_mtu() to prevent buffer overflow
[ Upstream commit ac1c7656fa717f29fac3ea073af63f0b9919ec9a ]

Sending an PF_PACKET allows to bypass the CAN framework logic and to
directly reach the xmit() function of a CAN driver. The only check
which is performed by the PF_PACKET framework is to make sure that
skb->len fits the interface's MTU.

Unfortunately, because the sun4i_can driver does not populate its
net_device_ops->ndo_change_mtu(), it is possible for an attacker to
configure an invalid MTU by doing, for example:

  $ ip link set can0 mtu 9999

After doing so, the attacker could open a PF_PACKET socket using the
ETH_P_CANXL protocol:

	socket(PF_PACKET, SOCK_RAW, htons(ETH_P_CANXL))

to inject a malicious CAN XL frames. For example:

	struct canxl_frame frame = {
		.flags = 0xff,
		.len = 2048,
	};

The CAN drivers' xmit() function are calling can_dev_dropped_skb() to
check that the skb is valid, unfortunately under above conditions, the
malicious packet is able to go through can_dev_dropped_skb() checks:

  1. the skb->protocol is set to ETH_P_CANXL which is valid (the
     function does not check the actual device capabilities).

  2. the length is a valid CAN XL length.

And so, hi3110_hard_start_xmit() receives a CAN XL frame which it is
not able to correctly handle and will thus misinterpret it as a CAN
frame. The driver will consume frame->len as-is with no further
checks.

This can result in a buffer overflow later on in hi3110_hw_tx() on
this line:

	memcpy(buf + HI3110_FIFO_EXT_DATA_OFF,
	       frame->data, frame->len);

Here, frame->len corresponds to the flags field of the CAN XL frame.
In our previous example, we set canxl_frame->flags to 0xff. Because
the maximum expected length is 8, a buffer overflow of 247 bytes
occurs!

Populate net_device_ops->ndo_change_mtu() to ensure that the
interface's MTU can not be set to anything bigger than CAN_MTU. By
fixing the root cause, this prevents the buffer overflow.

Fixes: 57e83fb9b7 ("can: hi311x: Add Holt HI-311x CAN driver")
Signed-off-by: Vincent Mailhol <mailhol@kernel.org>
Link: https://patch.msgid.link/20250918-can-fix-mtu-v1-2-0d1cada9393b@kernel.org
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-10-02 13:34:33 +02:00
..
accessibility
acpi ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value 2025-08-28 16:21:33 +02:00
amba
android
ata ata: Fix SATA_MOBILE_LPM_POLICY description in Kconfig 2025-08-28 16:21:35 +02:00
atm atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). 2025-09-04 14:05:54 +02:00
auxdisplay
base pmdomain: governor: Consider CPU latency tolerance from pm_domain_cpu_gov 2025-08-28 16:21:34 +02:00
bcma
block drbd: add missing kref_get in handle_write_conflicts 2025-08-28 16:21:24 +02:00
bluetooth Bluetooth: btrtl: Prevent potential NULL dereference 2025-05-02 07:39:19 +02:00
bus Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect devices first" 2025-06-27 11:02:55 +01:00
cdrom
char ipmi: Fix strcpy source and destination the same 2025-08-28 16:21:29 +02:00
clk clk: sunxi-ng: v3s: Fix de clock definition 2025-08-28 16:21:20 +02:00
clocksource clocksource/i8253: Use raw_spinlock_irqsave() in clockevent_i8253_disable() 2025-06-04 14:32:29 +02:00
connector
counter
cpufreq cpufreq: armada-8k: Fix off by one in armada_8k_cpufreq_free_table() 2025-08-28 16:21:30 +02:00
cpuidle cpuidle: menu: Avoid discarding useful information 2025-06-04 14:32:32 +02:00
crypto crypto: qat - fix seq_file position update in adf_ring_next() 2025-08-28 16:21:21 +02:00
dax
dca
devfreq
dio
dma dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees 2025-10-02 13:34:29 +02:00
dma-buf dma-buf: fix timeout handling in dma_resv_wait_timeout v2 2025-07-17 18:25:04 +02:00
edac EDAC/altera: Delete an inappropriate dma_free_coherent() call 2025-10-02 13:34:27 +02:00
eisa
extcon
firewire
firmware firmware: psci: Fix refcount leak in psci_dt_init 2025-06-27 11:02:46 +01:00
fpga fpga: zynq_fpga: Fix the wrong usage of dma_map_sgtable() 2025-08-28 16:21:32 +02:00
fsi
gnss
gpio gpio: pca953x: fix IRQ storm on system wake up 2025-09-09 18:44:00 +02:00
gpu drm/amdgpu: drop hw access in non-DC audio fini 2025-09-09 18:43:59 +02:00
greybus
hid HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() 2025-09-04 14:05:56 +02:00
hsi HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition 2025-05-02 07:39:18 +02:00
hv
hwmon hwmon: (occ) fix unaligned accesses 2025-06-27 11:02:57 +01:00
hwspinlock
hwtracing coresight: catu: Fix number of pages while using 64k pages 2025-04-10 14:29:41 +02:00
i2c i2c: qup: jump out of the loop in case of timeout 2025-08-28 16:21:17 +02:00
i3c i3c: don't fail if GETHDRCAP is unsupported 2025-08-28 16:21:29 +02:00
ide
idle
iio iio: light: opt3001: fix deadlock due to concurrent flag access 2025-09-09 18:44:00 +02:00
infiniband IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions 2025-10-02 13:34:33 +02:00
input Input: xpad - set correct controller type for Acer NGR200 2025-08-28 16:21:14 +02:00
interconnect
iommu iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid 2025-06-04 14:32:26 +02:00
ipack
irqchip irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode() 2025-06-04 14:32:25 +02:00
isdn mISDN: Fix memory leak in dsp_hwec_enable() 2025-09-09 18:43:57 +02:00
leds
lightnvm
macintosh
mailbox mailbox: Not protect module_put with spin_lock_irqsave 2025-07-17 18:24:49 +02:00
mcb mcb: fix a double free bug in chameleon_parse_gdd() 2025-05-02 07:39:26 +02:00
md md/raid1: Fix stack memory use after return in raid1_reshape 2025-07-17 18:25:04 +02:00
media media: venus: hfi: explicitly release IRQ during teardown 2025-08-28 16:21:35 +02:00
memory
memstick memstick: Fix deadlock by moving removing flag earlier 2025-08-28 16:21:32 +02:00
message
mfd mfd: max14577: Fix wakeup source leaks on device unbind 2025-07-17 18:24:49 +02:00
misc misc: rtsx: usb: Ensure mmc child device is active when card is present 2025-08-28 16:21:30 +02:00
mmc mmc: mvsdio: Fix dma_unmap_sg() nents value 2025-10-02 13:34:31 +02:00
mtd mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing 2025-10-02 13:34:28 +02:00
mux
net can: hi311x: populate ndo_change_mtu() to prevent buffer overflow 2025-10-02 13:34:33 +02:00
nfc
ntb ntb: reduce stack usage in idt_scan_mws 2025-05-02 07:39:28 +02:00
nubus
nvdimm libnvdimm/labels: Fix divide error in nd_label_data_init() 2025-06-04 14:32:30 +02:00
nvme nvmet-tcp: don't restore null sk_state_change 2025-06-04 14:32:35 +02:00
nvmem
of of: module: add buffer overflow check in of_modalias() 2025-06-04 14:32:25 +02:00
opp
oprofile
parisc
parport
pci PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports 2025-08-28 16:21:33 +02:00
pcmcia pcmcia: omap_cf: Mark driver struct with __refdata to prevent section mismatch 2025-10-02 13:34:30 +02:00
perf perf: arm_pmu: Don't disable counter in armpmu_add() 2025-05-02 07:39:09 +02:00
phy phy: ti-pipe3: fix device leak at unbind 2025-10-02 13:34:30 +02:00
pinctrl pinctrl: STMFX: add missing HAS_IOMEM dependency 2025-09-04 14:05:53 +02:00
platform platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches 2025-08-28 16:21:25 +02:00
pnp
power power: supply: bq27xxx: restrict no-battery detection to bq27000 2025-10-02 13:34:31 +02:00
powercap
pps pps: fix poll support 2025-08-28 16:21:18 +02:00
ps3
ptp
pwm pwm: mediatek: Fix duty and period setting 2025-08-28 16:21:35 +02:00
rapidio drivers/rapidio/rio_cm.c: prevent possible heap overwrite 2025-06-27 11:02:56 +01:00
ras
regulator regulator: core: fix NULL dereference on unbind due to stale coupling data 2025-08-28 16:21:17 +02:00
remoteproc
reset
rpmsg rpmsg: qcom_smd: Fix uninitialized return variable in __qcom_smd_send() 2025-06-27 11:02:48 +01:00
rtc rtc: ds1307: handle oscillator stop flag (OSF) for ds1341 2025-08-28 16:21:35 +02:00
s390 scsi: s390: zfcp: Ensure synchronous unit_add 2025-06-27 11:02:56 +01:00
sbus
scsi scsi: lpfc: Fix buffer free/clear order in deferred receive path 2025-09-09 18:43:59 +02:00
sfi
sh
siox
slimbus
soc soc: qcom: mdt_loader: Deal with zero e_shentsize 2025-10-02 13:34:30 +02:00
soundwire soundwire: stream: restore params when prepare ports fail 2025-08-28 16:21:21 +02:00
spi spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort 2025-09-09 18:44:01 +02:00
spmi
ssb
staging comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large 2025-08-28 16:21:33 +02:00
target scsi: target: iscsi: Fix timeout on deleted connection 2025-06-04 14:32:29 +02:00
tc
tee tee: Prevent size calculation wraparound on 32-bit kernels 2025-06-27 11:02:55 +01:00
thermal thermal: sysfs: Return ENODATA instead of EAGAIN for reads 2025-08-28 16:21:25 +02:00
thunderbolt thunderbolt: Fix copy+paste error in match_service_id() 2025-08-28 16:21:30 +02:00
tty serial: sc16is7xx: fix bug in flow control levels init 2025-10-02 13:34:32 +02:00
uio uio_hv_generic: Use correct size for interrupt and monitor pages 2025-06-27 11:02:52 +01:00
usb usb: core: Add 0x prefix to quirks debug output 2025-10-02 13:34:33 +02:00
vfio
vhost vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put() 2025-09-04 14:05:53 +02:00
video Revert "vgacon: Add check for vc_origin address range in vgacon_scroll()" 2025-08-28 16:21:31 +02:00
virt
virtio
visorbus
vlynq
vme
w1
watchdog watchdog: dw_wdt: Fix default timeout 2025-08-28 16:21:27 +02:00
xen xen/swiotlb: relax alignment requirements 2025-06-04 14:32:37 +02:00
zorro
Kconfig
Makefile