CVE-2025-38665

can: netlink: can_changelink(): fix NULL pointer deref of struct can_priv::do_set_mode

References

Notes

 carnil> Introduced in 39549eef3587 ("can: CAN Network device driver and Netlink
 carnil> interface"). Vulnerable versions: 2.6.31.

Bugs

Status

Branch Status
upstream released (6.16) [c1f3f9797c1f44a762e6f5f72520b2e520537b52]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.15-upstream-stable released (6.15.9) [6acceb46180f9e160d4f0c56fcaf39ba562822ae]
6.12-upstream-stable released (6.12.41) [0ca816a96fdcf32644c80cbe7a82c7b6ce6ddda5]
6.6-upstream-stable released (6.6.101) [cf81a60a973358dea163f6b14062f17831ceb894]
6.1-upstream-stable released (6.1.148) [6bbcf37c5114926c99a1d1e6993a5b35689d2599]
5.10-upstream-stable needed
sid released (6.16.3-1)
6.12-trixie-security released (6.12.41-1)
6.1-bookworm-security released (6.1.148-1)
5.10-bullseye-security needed