CVE-2023-52878

can: dev: can_put_echo_skb(): don't crash kernel if can_priv::echo_skb is accessed out of bounds

References

Notes

 carnil> Introduced in a6e4bc530403 ("can: make the number of echo skb's configurable").
 carnil> Vulnerable versions: 2.6.33-rc1.

Bugs

Status

Branch Status
upstream released (6.7-rc1) [6411959c10fe917288cbb1038886999148560057]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.8-upstream-stable N/A "Fixed before branching point"
6.6-upstream-stable released (6.6.2) [8ab67da060157362b2e0926692c659808784708f]
6.1-upstream-stable released (6.1.63) [0d30931f1fa0fb893fb7d5dc32b6b7edfb775be4]
5.10-upstream-stable needed
sid released (6.5.13-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.64-1)
5.10-bullseye-security needed