include/linux/can/dev.h | 5 +++++ 1 file changed, 5 insertions(+)
Valid CAN XL skbs can be injected through AF_PACKET. Although
can_dropped_invalid_skb() verifies the CAN XL frame layout, it does not
check whether CAN XL is enabled on the target device.
can_dev_dropped_skb() already rejects CAN FD skbs when CAN FD is
disabled, but lacks the equivalent CAN XL check. Consequently, drivers
without CAN XL support may interpret a CAN XL skb as struct canfd_frame
or struct can_frame.
For example, rockchip_canfd interprets the mandatory CANXL_XLF flag at
offset 4 as struct canfd_frame.len. The resulting value is at least 128,
so the driver reads beyond the skb frame data and writes beyond the
controller TX data register window.
Reject CAN XL skbs in the common transmit validation helper unless
CAN_CTRLMODE_XL is enabled.
Fixes: fb08cba12b52 ("can: canxl: update CAN infrastructure for CAN XL frames")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-can/20260731105402.B7A451F000E9@smtp.kernel.org/
Cc: stable@vger.kernel.org
Signed-off-by: Cunhao Lu <1579567540@qq.com>
---
include/linux/can/dev.h | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/include/linux/can/dev.h b/include/linux/can/dev.h
index 6d0710d6f571..13fa607474b7 100644
--- a/include/linux/can/dev.h
+++ b/include/linux/can/dev.h
@@ -167,6 +167,11 @@ static inline bool can_dev_dropped_skb(struct net_device *dev, struct sk_buff *s
goto invalid_skb;
}
+ if (!(priv->ctrlmode & CAN_CTRLMODE_XL) && can_is_canxl_skb(skb)) {
+ netdev_info_once(dev, "CAN XL is disabled, dropping skb\n");
+ goto invalid_skb;
+ }
+
if (can_dev_in_xl_only_mode(priv) && !can_is_canxl_skb(skb)) {
netdev_info_once(dev,
"Error signaling is disabled, dropping skb\n");
---
base-commit: 02dc699f83d04069fdabc996fc22d47cda47a4a9
change-id: 20260801-master-bc2e15d668f5
Best regards,
--
Cunhao Lu <1579567540@qq.com>
Thanks for your patch.
Please take a look at the latest activities on the Linux-CAN ML.
There's already a patch available I would prefer to solve the issue:
https://lore.kernel.org/linux-can/20260731-drop_canxl_frames-v1-1-7387b70353b3@kernel.org/
Many thanks,
Oliver
On 01.08.26 11:29, Cunhao Lu wrote:
> Valid CAN XL skbs can be injected through AF_PACKET. Although
> can_dropped_invalid_skb() verifies the CAN XL frame layout, it does not
> check whether CAN XL is enabled on the target device.
>
> can_dev_dropped_skb() already rejects CAN FD skbs when CAN FD is
> disabled, but lacks the equivalent CAN XL check. Consequently, drivers
> without CAN XL support may interpret a CAN XL skb as struct canfd_frame
> or struct can_frame.
>
> For example, rockchip_canfd interprets the mandatory CANXL_XLF flag at
> offset 4 as struct canfd_frame.len. The resulting value is at least 128,
> so the driver reads beyond the skb frame data and writes beyond the
> controller TX data register window.
>
> Reject CAN XL skbs in the common transmit validation helper unless
> CAN_CTRLMODE_XL is enabled.
>
> Fixes: fb08cba12b52 ("can: canxl: update CAN infrastructure for CAN XL frames")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://lore.kernel.org/linux-can/20260731105402.B7A451F000E9@smtp.kernel.org/
> Cc: stable@vger.kernel.org
> Signed-off-by: Cunhao Lu <1579567540@qq.com>
> ---
> include/linux/can/dev.h | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/include/linux/can/dev.h b/include/linux/can/dev.h
> index 6d0710d6f571..13fa607474b7 100644
> --- a/include/linux/can/dev.h
> +++ b/include/linux/can/dev.h
> @@ -167,6 +167,11 @@ static inline bool can_dev_dropped_skb(struct net_device *dev, struct sk_buff *s
> goto invalid_skb;
> }
>
> + if (!(priv->ctrlmode & CAN_CTRLMODE_XL) && can_is_canxl_skb(skb)) {
> + netdev_info_once(dev, "CAN XL is disabled, dropping skb\n");
> + goto invalid_skb;
> + }
> +
> if (can_dev_in_xl_only_mode(priv) && !can_is_canxl_skb(skb)) {
> netdev_info_once(dev,
> "Error signaling is disabled, dropping skb\n");
>
> ---
> base-commit: 02dc699f83d04069fdabc996fc22d47cda47a4a9
> change-id: 20260801-master-bc2e15d668f5
>
> Best regards,
> --
> Cunhao Lu <1579567540@qq.com>
>
© 2016 - 2026 Red Hat, Inc.