CVE-2022-48830: can: isotp: fix potential CAN frame reception race in isotp_rcv()
In the Linux kernel, the following vulnerability has been resolved:
can: isotp: fix potential CAN frame reception race in isotprcv()
When receiving a CAN frame the current code logic does not consider concurrently receiving processes which do not show up in real world usage.
Ziyang Xuan writes:
The following syz problem is one of the scenarios. so->rx.len is changed by isotprcvff() during isotprcvcf(), so->rx.len equals 0 before allocskb() and equals 4096 after allocskb(). That will trigger skboverpanic() in skbput().
======================================================= CPU: 1 PID: 19 Comm: ksoftirqd/1 Not tainted 5.16.0-rc8-syzkaller #0 RIP: 0010:skbpanic+0x16c/0x16e net/core/skbuff.c:113 Call Trace: <TASK> skboverpanic net/core/skbuff.c:118 [inline] skbput.cold+0x24/0x24 net/core/skbuff.c:1990 isotprcvcf net/can/isotp.c:570 [inline] isotprcv+0xa38/0x1e30 net/can/isotp.c:668 deliver net/can/afcan.c:574 [inline] canrcvfilter+0x445/0x8d0 net/can/afcan.c:635 canreceive+0x31d/0x580 net/can/afcan.c:665 canrcv+0x120/0x1c0 net/can/afcan.c:696 netifreceiveskbonecore+0x114/0x180 net/core/dev.c:5465 netifreceiveskb+0x24/0x1b0 net/core/dev.c:5579
Therefore we make sure the state changes and data structures stay consistent at CAN frame reception time by adding a spinlock in isotprcv(). This fixes the issue reported by syzkaller but does not affect real world operation.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
can: isotp: fix potential CAN frame reception race in isotprcv()
When receiving a CAN frame the current code logic does not consider concurrently receiving processes which do not show up in real world usage.
Ziyang Xuan writes:
The following syz problem is one of the scenarios. so-rx.len is changed by isotprcvff() during isotprcvcf(), so-rx.len equals 0 before allocskb() and equals 4096 after allocskb(). That will trigger skboverpanic() in skbput().
======================================================= CPU: 1 PID: 19 Comm: ksoftirqd/1 Not tainted 5.16.0-rc8-syzkaller #0 RIP: 0010:skbpanic+0x16c/0x16e net/core/skbuff.c:113 Call Trace: TASK skboverpanic net/core/skbuff.c:118 [inline] skbput.cold+0x24/0x24 net/core/skbuff.c:1990 isotprcvcf net/can/isotp.c:570 [inline] isotprcv+0xa38/0x1e30 net/can/isotp.c:668 deliver net/can/afcan.c:574 [inline] canrcvfilter+0x445/0x8d0 net/can/afcan.c:635 canreceive+0x31d/0x580 net/can/afcan.c:665 canrcv+0x120/0x1c0 net/can/afcan.c:696 netifreceiveskbonecore+0x114/0x180 net/core/dev.c:5465 netifreceiveskb+0x24/0x1b0 net/core/dev.c:5579
Therefore we make sure the state changes and data structures stay consistent at CAN frame reception time by adding a spinlock in isotprcv(). This fixes the issue reported by syzkaller but does not affect real world operation.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.10.101 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.15.24 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.16.10 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.17
Event History
Frequently Asked Questions
What is the severity of CVE-2022-48830?
CVE-2022-48830 has been classified with a low severity due to its limited impact on real-world usage.
How do I fix CVE-2022-48830?
To fix CVE-2022-48830, update your Linux kernel to version 5.16.0 or later where the issue has been addressed.
What systems are affected by CVE-2022-48830?
CVE-2022-48830 specifically affects the Linux kernel version 5.16.0-rc8.
What type of vulnerability is CVE-2022-48830?
CVE-2022-48830 is a race condition vulnerability that may affect the reception of CAN frames in concurrent processing.
Is CVE-2022-48830 exploitable?
CVE-2022-48830 is not considered exploitable in typical usage scenarios as it pertains to concurrent CAN frame reception.