In the Linux kernel, the following vulnerability has been resolved:
can: m_can: m_can_{read_fifo,echo_tx_event}(): shift timestamp to full 32 bits
In commit 1be37d3b0414 ("can: m_can: fix periph RX path: use rx-offload to ensure skbs are sent from softirq context") the RX path for peripheral devices was switched to RX-offload.
Received CAN frames are pushed to RX-offload together with a timestamp. RX-offload is designed to handle overflows of the timestamp correctly, if 32 bit timestamps are provided.
The timestamps of m_can core are only 16 bits wide. So this patch shifts them to full 32 bit before passing them to RX-offload.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-riscv-5.15Upgrade linux-awsUpgrade linuxUpgrade linux-gkeopUpgrade linux-gkeUpgrade linux-gcpUpgrade linux-gcp-5.15Upgrade linux-oracle-5.15Upgrade linux-ibmUpgrade linux-raspiUpgrade linux-aws-5.15Upgrade linux-realtimeUpgrade linux-oracleUpgrade linux-lowlatencyUpgrade linux-lowlatency-hwe-5.15Upgrade linux-hwe-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-kvmUpgrade linux-azure-5.15Upgrade linux-intel-iotgUpgrade linux-azureUpgrade linux-nvidia | Mar 19, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub