From nobody Mon Sep 28 17:48:37 2026 Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 342C0348C7B for ; Tue, 18 Aug 2026 21:50:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.46 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787089836; cv=none; b=fdPhYJ9YrAaOje+wCOVk5Dcxra2QIdjl0xZ2Z0obExyID6zTP0d2u+SUHL4lZHFQKm4zVIoeDHcip9z1Nrz1+xik2XxtuxuWkYd2ZT6p7t1agQyLho8LPbANy98V4gtVEJ/g0MUxVymMZRrFEyZxkcgbmxBWFTom229UXrmNdE4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787089836; c=relaxed/simple; bh=LbviQGy33/VrflqEdGmEC31Fge9f4eLgCpK74UV/Mto=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=dYLm/eGDxkR00XUeB0VZNRUwN5LMl2ZuhP/S6A7V7QoUa9hbtgTkRGSLxZk7NrWNaMcO0QjZKjAGHRgKuHK9uazlWXUyJe1inx7CF28dkEiv4M2K1g87xTPl3TeFSBXhtEXi2FpZ9ypCjZup1ozyiAtOy/UwqlWAkjkvZxMR3Ok= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xbow.com; spf=pass smtp.mailfrom=xbow.com; dkim=pass (2048-bit key) header.d=xbow.com header.i=@xbow.com header.b=LbWe7fNv; arc=none smtp.client-ip=209.85.216.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xbow.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xbow.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xbow.com header.i=@xbow.com header.b="LbWe7fNv" Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-38dc69c74b8so555150a91.0 for ; Tue, 18 Aug 2026 14:50:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xbow.com; s=google; t=1787089834; x=1787694634; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=nB44X2BHNRtk2rWj3ofb0fstOoc1QxVcXE0ahPC36tk=; b=LbWe7fNvj+ltC538owXMeJyCdjc4RjHgMl8nm9qBk3Z0yzDKbw1HxXZBO/UhbDeSXg 6HHUAEDv7RFEBwITlcrXOtX0u9IbIXmCxaj/9YZxO8pnmrKTBKDp2b1pqNnl/omK3TCw TxwyxAIyJVCyJ6Nr64BIbFBiMkc6dEB8jQv/Nx99bKzEEMoONJp0LU7Mqx2kTnOCAuip XKXaSFmvzaB3nJZksgla5aKG/maXScVXJoe8RbijisTCuWBUL8KnbxIfsHx4XFQHHFCk 6f6CXJ338/lyJrwBgZ284TJGEeHRWY9oKMIkUkf3QbPP1KvSSDyIxGE2r/X8zBMbOEa8 KCXA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787089834; x=1787694634; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=nB44X2BHNRtk2rWj3ofb0fstOoc1QxVcXE0ahPC36tk=; b=hYHnw7bv8WHCW/cAv5vdJSfujF6vkKdgbqtaKrEBKImF94NlMqClfXEV5aoAV3AeiB VCxkjFW4sIrjsAGZQ4y73umUtyjh2AZX7TTYZ7DMy2vPTwfghUkW4QthgS0EPIVmYdYN 2c9DqLyMu9mLDLti6w5W8Hy2qgtROj4F4RBsFGZ3757jZixGz+m4ByRykjzxZjuBtOIE s8wTh6nbqApEuYezuKiHvJY0b9gazNrjKew1FLnB9imIEJ2JqKHklUWPQJZsxKlxTeZq 7GHKaz/PuuCc0FegEaKD33ChmM+iQ73akKkxc1YZ1umlnmSMx+J83ITZ5BHA+QLmD5aV l5EQ== X-Forwarded-Encrypted: i=1; AHgh+RpVWUBn9IPXdf7gr3LNGOysYpfvendaXwWm3JvcvtFbZhfXl4MRR3Us2BE1WDnv/j+nPoDdCxedzCPMooU=@vger.kernel.org X-Gm-Message-State: AOJu0Yx2iZ1zQiGJr28UizSjVI00xo01jM5ahmXihBmCGGuN7WG9yoCo 7KeIOHeZVlX+ZP9Kaud7VayX+5Gvtj3ifkHmA86c/awoWSr3hy1xwmot05v76XaCZdM= X-Gm-Gg: AR+sD12jAhBIBtuzKJAjCYDn8qQr78+ZnHBfWSGwgiINEyEOnohx/56aEUFQboO4EJ5 VHKbSY9Kgc+rQNLceG6RmeHRMNyshOYpsGMlAFRtajw0Jzs9S/axdeBnRGkPniobzSaqWgKzf2p Gog3KxSqqzh8s8ENw7LRQ/Rsc+3KECVHB9yO1tUpoIi34f0Hxs2O2mpYpAejFYh0pWizmEOMhFw 1IxTyaQvnWRH20iyq1vpSzYUF+Yq2CQEGTXvgVMqMZsWENDeNrpwRMvtQu/UGsNsB8trRobQJdR eGFfj8UTWljzrf/rp391dBOYVbVJgbe7WQrl67UE3+HY57BpeVd6mJAHWaNdjveIYv0pVds5olr d52reNbmjewjaDcAxQkHgwyGpXOX6dBmIboJidb64hVU4fjbH31ah06C9ob5GJU1JJ3LsTwP/Mp fg+5l2X9164QH/w+r/dS+/qM+He+VeS+2cPhplxMdVdCGKCh3xh2nLBUFRFRdb57Dg+CE0QaDp/ yumqZYYnDTyEXiBUljw08SXBAvT X-Received: by 2002:a17:90a:da84:b0:38e:97f0:aa4b with SMTP id 98e67ed59e1d1-3957b38f768mr1186311a91.13.1787089834370; Tue, 18 Aug 2026 14:50:34 -0700 (PDT) Received: from Mac.lan ([125.128.148.126]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3957fbbf8a7sm127600a91.16.2026.08.18.14.50.32 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 18 Aug 2026 14:50:33 -0700 (PDT) From: Baul Lee To: max@enpas.org, mkl@pengutronix.de, mailhol@kernel.org Cc: linux-can@vger.kernel.org, linux-kernel@vger.kernel.org, federico.kirschbaum@xbow.com Subject: [PATCH net] can: can327: Fix out-of-bounds write in can327_parse_frame() Date: Wed, 19 Aug 2026 06:50:29 +0900 Message-ID: <20260818215029.47758-1-baul.lee@xbow.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" can327_parse_frame() assigns the CAN payload length from the DLC nibble of the adapter's ASCII frame line, hex_to_bin(elm->rxbuf[datastart - 2]), without validating it. A standard-format line only has to satisfy rxbuf[3] =3D=3D ' ' and rxbuf[5] =3D=3D ' ', so the DLC nibble rxbuf[4] can= be a space, for which hex_to_bin() returns -1, and that becomes 255 in the u8 frame->len. A hex nibble of 9 to f is not rejected either, while CAN_MAX_DLEN is 8. frame->data[] is the 8-byte payload of the 16-byte struct can_frame returned by alloc_can_skb(), so the data-nibble loop writes up to 255 device-controlled bytes, 247 of them past the frame and over the trailing skb_shared_info. The length check before the loop only requires the line to be frame->len * 3 + datastart bytes, which a long enough line of hex and spaces satisfies. Freeing the corrupted skb then faults: pc : skb_release_data+0xf4/0x200 Call trace: skb_release_data+0xf4/0x200 (P) sk_skb_reason_drop+0x40/0xa4 can_rcv+0x6c/0xbc __netif_receive_skb_one_core+0x40/0x4c can327_ldisc_rx+0xc8/0x140 tty_ldisc_receive_buf+0x48/0x60 flush_to_ldisc+0xdc/0x1b0 Kernel panic - not syncing: Oops: Fatal exception in interrupt Reject the line when the nibble is not a hex digit or exceeds CAN_MAX_DLEN, as the parser already does for other malformed lines. Attaching the N_CAN327 line discipline requires CAP_NET_ADMIN, but the frame lines then come from the ELM327 device, so a malicious adapter reaches this path with device-controlled data. Discovered by XBOW, triaged by Baul Lee Fixes: 43da2f07622f ("can: can327: CAN/ldisc driver for ELM327 based OBD-II= adapters") Signed-off-by: Baul Lee Reviewed-by: Max Staudt --- drivers/net/can/can327.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/net/can/can327.c b/drivers/net/can/can327.c index 90f5e35f3c8f..c76a6378d4d6 100644 --- a/drivers/net/can/can327.c +++ b/drivers/net/can/can327.c @@ -395,6 +395,7 @@ static int can327_parse_frame(struct can327 *elm, size_= t len) struct sk_buff *skb; int hexlen; int datastart; + int dlc; int i; =20 lockdep_assert_held(&elm->lock); @@ -460,7 +461,13 @@ static int can327_parse_frame(struct can327 *elm, size= _t len) */ =20 /* Read CAN data length */ - frame->len =3D (hex_to_bin(elm->rxbuf[datastart - 2]) << 0); + dlc =3D hex_to_bin(elm->rxbuf[datastart - 2]); + if (dlc < 0 || dlc > CAN_MAX_DLEN) { + /* Not a hex digit, or more than CAN_MAX_DLEN bytes. */ + kfree_skb(skb); + return -ENODATA; + } + frame->len =3D dlc; =20 /* Read CAN ID */ if (frame->can_id & CAN_EFF_FLAG) { --=20 2.50.1