From nobody Mon Sep 28 18:33:56 2026 Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2360F263F44 for ; Tue, 18 Aug 2026 22:18:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787091505; cv=none; b=aA4FqxRrfym5uRaZnyF1CgEgD1zAaGJ4v3UsXNtnm40U2qW4He/zTicQQcqMC0DuS28HLxvQYze9x0FN9eRiDiwdtTexORg2ysvvwGDyUDJtyRMtktQjkhAJKh8TJYdiTrPSiZWwqQyTtOm6K0sn0LrpHqAm/dsJrZ8EKEqj2RM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787091505; c=relaxed/simple; bh=xeb+tFMObI7h3eVoQvB19uHowJe0ECQUjezaWgqLXiE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=SWswKvK6ttu+IQktGWuuHp2CTl9uERaMHxXHlVXpxdEMyO+fnk1+iooQQ7ub/CuEt3dBa3n8TKPEm7Clpc+JFkoSO2Q+WU94M5GAuly2bmT+AfsSSnD44bv2gKaMamOb5ztWIjW2BZE9hdsx5Wep7OPA3ZTn8WKR7cuEg7SO+9k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xbow.com; spf=pass smtp.mailfrom=xbow.com; dkim=pass (2048-bit key) header.d=xbow.com header.i=@xbow.com header.b=lUISu/hH; arc=none smtp.client-ip=209.85.216.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=xbow.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xbow.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=xbow.com header.i=@xbow.com header.b="lUISu/hH" Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-38dc69c74b8so578042a91.0 for ; Tue, 18 Aug 2026 15:18:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=xbow.com; s=google; t=1787091503; x=1787696303; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=d0XU4Swy3+99fCdFDFJ5dFoqIG7hfBf1CedXoWdbxRw=; b=lUISu/hH9KlXRzeS7bl8bHNUc/F828y8S70xyKZYg5ur0/gHx1w7/SDkYPgvAOf/qn QCBN9NrIeRR4DzKawhwzII0RVeusMrw+z39qgMrxVMqqI8s61hb/mrBvlLREVaVN83O8 mOrpMi6yYge/c+zU/dF0TJDuvAalQ9FtCJ0/x8PnvPhGlqqjsShr2tpEw0GmGI120yWv UbMBmWLLW9AC5RFNIzPocMGjGus1w0U/iCNwN3Dlhr2dLFuEhTUyCZ46uqOVIvFbfB/g VghPYclYMyyph6vuDXdIqapTHEdn47gBzorSEvn97+hcP+51N/vzq/4hEZeFnDovAnbu 1FZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787091503; x=1787696303; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=d0XU4Swy3+99fCdFDFJ5dFoqIG7hfBf1CedXoWdbxRw=; b=AnZK6NIqJrNs7tNu3YUDueuc7lulEWfcS/79UtEEuj9gRkkqEtuaVNIqp9h0HR7x0A 8xswkyOA0efUcQiEXD+UxwR4xgCW3UblECAQMCj7YGHaf/YKRCnEZ/RTzVu4NM0hwU8g eo25LrI0Zv2dtia1GOWPRx102E0TwqKU+8xTRAiciek0CFE7okwiMT2zD0+GTDCXIS+8 vk5oY5oE035O73WMBfFMwVpFk1dNP4cccbPZjJ0SmvWgZRW0u2nVYSKgHQD1Ky66oWDb rEYoptVKQy4DnBNxmcfyRaiLqwBsK6J7bXXyTY1hN4NF6lk2LLquuxMbbATgnsD1tuak PG6Q== X-Forwarded-Encrypted: i=1; AHgh+RpiNNIUTuXZfxXdDwPP0p5aEoZpOSnJmHBEtb/i0+XluSJ2E6eAZO7h+6VtgkCY7Kv2m57gMsgocp9LygQ=@vger.kernel.org X-Gm-Message-State: AOJu0YyVqZE5BSPrBBb0DvgOCe5CPtyxR8XvZjQ3ds8RUZ1JT89pBA7r WR02g1qrtN81U1gOT/VSE9KN0mc4APPorlZeD/YxlK355EpfwTW4EIUrh4z2THTibMw= X-Gm-Gg: AR+sD12/ye+YGTmcP5QUiC58otQrzCgQKw7ZwhIKL5gW4h/wccynjf6Ghs2kYfgVjhq X5pUBdahKo5mjFYHZUX/NHH9oxpxEXflxOA0uSo3iB5Af54yQDya4fwM6tT7c6xJqo8zBnfPKti 4GVtqbLJNNDbIIjItkYxXmzk/FFGpgFMPtA9885wp2/0YoKNS7FV6A2r6WeftLTzB43NDu3LST7 Qsm3Erp5d7HM7Shr5Q392jWKsKaJ/PzCkuLU4i+3gnLMB63p4JRZwEWyBK2m2Y5iV4MF1Cv5ZeP bV+CaDqZyQZYtsu0/xJvCU/X+cjvQ6FuMyRAZOveOPfoNNfCG+bt7YMfks+/f4KuRk4cJTR2wfz 8Y7FiNV2ld23ujgz7SAHTkE0vq+AF6HpOCqCTcDC7Byx8lDp/IP+6rrNifm/92cmRUt1M4WQOk5 hTTLSKhwA0Ffvl3SHCakD0RS3JR+LO4bxrVsnFp7b4TJcyHyrzqqQ/VnTeRWDG1RKzJT2lbA75G RGfNhCV/RKYx/sL0J+KXRMkX4em X-Received: by 2002:a17:90a:d604:b0:38e:97f0:aa4b with SMTP id 98e67ed59e1d1-3958127a5aamr68823a91.13.1787091503346; Tue, 18 Aug 2026 15:18:23 -0700 (PDT) Received: from Mac.lan ([125.128.148.126]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3957fbbf8a7sm187194a91.16.2026.08.18.15.18.21 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 18 Aug 2026 15:18:22 -0700 (PDT) From: Baul Lee To: max@enpas.org, mkl@pengutronix.de, mailhol@kernel.org Cc: linux-can@vger.kernel.org, linux-kernel@vger.kernel.org, federico.kirschbaum@xbow.com Subject: [PATCH net v2] can: can327: Fix out-of-bounds write in can327_parse_frame() Date: Wed, 19 Aug 2026 07:18:18 +0900 Message-ID: <20260818221818.49430-1-baul.lee@xbow.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" can327_parse_frame() assigns the CAN payload length from the DLC nibble of the adapter's ASCII frame line, hex_to_bin(elm->rxbuf[datastart - 2]), without validating it. A standard-format line only has to satisfy rxbuf[3] =3D=3D ' ' and rxbuf[5] =3D=3D ' ', so the DLC nibble rxbuf[4] can= be a space, for which hex_to_bin() returns -1, and that becomes 255 in the u8 frame->len. A hex nibble of 9 to f is not rejected either, while CAN_MAX_DLEN is 8. frame->data[] is the 8-byte payload of the 16-byte struct can_frame returned by alloc_can_skb(), so the data-nibble loop writes up to 255 device-controlled bytes, 247 of them past the frame and over the trailing skb_shared_info. The length check before the loop only requires the line to be frame->len * 3 + datastart bytes, which a long enough line of hex and spaces satisfies. Freeing the corrupted skb then faults: pc : skb_release_data+0xf4/0x200 Call trace: skb_release_data+0xf4/0x200 (P) sk_skb_reason_drop+0x40/0xa4 can_rcv+0x6c/0xbc __netif_receive_skb_one_core+0x40/0x4c can327_ldisc_rx+0xc8/0x140 tty_ldisc_receive_buf+0x48/0x60 flush_to_ldisc+0xdc/0x1b0 Kernel panic - not syncing: Oops: Fatal exception in interrupt Reject the line when the nibble is not a hex digit or exceeds CAN_MAX_DLEN, as the parser already does for other malformed lines. Attaching the N_CAN327 line discipline requires CAP_NET_ADMIN, but the frame lines then come from the ELM327 device, so a malicious adapter reaches this path with device-controlled data. Discovered by XBOW, triaged by Baul Lee Fixes: 43da2f07622f ("can: can327: CAN/ldisc driver for ELM327 based OBD-II= adapters") Cc: stable@vger.kernel.org Signed-off-by: Baul Lee Reviewed-by: Max Staudt --- v2: add Cc: stable and Max's Reviewed-by, as requested in review of v1 (https://lore.kernel.org/linux-can/20260818215029.47758-1-baul.lee@xbow= .com/). No change to the code. drivers/net/can/can327.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/net/can/can327.c b/drivers/net/can/can327.c index 90f5e35f3c8f..c76a6378d4d6 100644 --- a/drivers/net/can/can327.c +++ b/drivers/net/can/can327.c @@ -395,6 +395,7 @@ static int can327_parse_frame(struct can327 *elm, size_= t len) struct sk_buff *skb; int hexlen; int datastart; + int dlc; int i; =20 lockdep_assert_held(&elm->lock); @@ -460,7 +461,13 @@ static int can327_parse_frame(struct can327 *elm, size= _t len) */ =20 /* Read CAN data length */ - frame->len =3D (hex_to_bin(elm->rxbuf[datastart - 2]) << 0); + dlc =3D hex_to_bin(elm->rxbuf[datastart - 2]); + if (dlc < 0 || dlc > CAN_MAX_DLEN) { + /* Not a hex digit, or more than CAN_MAX_DLEN bytes. */ + kfree_skb(skb); + return -ENODATA; + } + frame->len =3D dlc; =20 /* Read CAN ID */ if (frame->can_id & CAN_EFF_FLAG) { --=20 2.50.1