Description
In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_tp_tx_dat_new(): fix out-of-bounds memory access In the j1939_tp_tx_dat_new() function, an out-of-bounds memory access could occur during the memcpy() operation if the size of skb->cb is larger than the size of struct j1939_sk_buff_cb. This is because the memcpy() operation uses the size of skb->cb, leading to a read beyond the struct j1939_sk_buff_cb. Updated the memcpy() operation to use the size of struct j1939_sk_buff_cb instead of the size of skb->cb. This ensures that the memcpy() operation only reads the memory within the bounds of struct j1939_sk_buff_cb, preventing out-of-bounds memory access. Additionally, add a BUILD_BUG_ON() to check that the size of skb->cb is greater than or equal to the size of struct j1939_sk_buff_cb. This ensures that the skb->cb buffer is large enough to hold the j1939_sk_buff_cb structure. [mkl: rephrase commit message]
Product status
9d71dd0c70099914fcd063135da3c580865e924c (git) before d2136f05690c272dfc9f9d6efcc51d5f53494b33
9d71dd0c70099914fcd063135da3c580865e924c (git) before 70caa596d158a5d84b117f722d58f3ea503a5ba9
9d71dd0c70099914fcd063135da3c580865e924c (git) before 4fe1d9b6231a68ffc91318f57fd8e4982f028cf7
9d71dd0c70099914fcd063135da3c580865e924c (git) before 4c3fb22a6ec68258ee129a2e6b720f43dffc562f
9d71dd0c70099914fcd063135da3c580865e924c (git) before 36befc9aed6202b4a9b906529aea13eacd7e34ff
9d71dd0c70099914fcd063135da3c580865e924c (git) before b45193cb4df556fe6251b285a5ce44046dd36b4a
5.4
Any version before 5.4
5.4.241 (semver)
5.10.178 (semver)
5.15.107 (semver)
6.1.24 (semver)
6.2.11 (semver)
6.3 (original_commit_for_fix)
References
git.kernel.org/...c/d2136f05690c272dfc9f9d6efcc51d5f53494b33
git.kernel.org/...c/70caa596d158a5d84b117f722d58f3ea503a5ba9
git.kernel.org/...c/4fe1d9b6231a68ffc91318f57fd8e4982f028cf7
git.kernel.org/...c/4c3fb22a6ec68258ee129a2e6b720f43dffc562f
git.kernel.org/...c/36befc9aed6202b4a9b906529aea13eacd7e34ff
git.kernel.org/...c/b45193cb4df556fe6251b285a5ce44046dd36b4a
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.