In the Linux kernel, the following vulnerability has been resolved:
can: af_can: fix NULL pointer dereference in can_rx_register()
It causes NULL pointer dereference when testing as following: (a) use syscall(__NR_socket, 0x10ul, 3ul, 0) to create netlink socket. (b) use syscall(__NR_sendmsg, ...) to create bond link device and vxcan link device, and bind vxcan device to bond device (can also use ifenslave command to bind vxcan device to bond device). (c) use syscall(__NR_socket, 0x1dul, 3ul, 1) to create CAN socket. (d) use syscall(__NR_bind, ...) to bind the bond device to CAN socket.
The bond device invokes the can-raw protocol registration interface to receive CAN packets. However, ml_priv is not allocated to the dev, dev_rcv_lists is assigned to NULL in can_rx_register(). In this case, it will occur the NULL pointer dereference issue.
The following is the stack information: BUG: kernel NULL pointer dereference, address: 0000000000000008 PGD 122a4067 P4D 122a4067 PUD 1223c067 PMD 0 Oops: 0000 [#1] PREEMPT SMP RIP: 0010:can_rx_register+0x12d/0x1e0 Call Trace: <TASK> raw_enable_filters+0x8d/0x120 raw_enable_allfilters+0x3b/0x130 raw_bind+0x118/0x4f0 __sys_bind+0x163/0x1a0 __x64_sys_bind+0x1e/0x30 do_syscall_64+0x35/0x80 entry_SYSCALL_64_after_hwframe+0x63/0xcd </TASK>
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-tools-develUpgrade kernel-headersUpgrade bpftool-debuginfoUpgrade kernel-livepatch-5.10.155-138.670Upgrade kernel-livepatch-5.15.79-51.138Upgrade perf-debuginfoUpgrade kernel-tools-debuginfoUpgrade python-perf-debuginfoUpgrade kernel-debuginfoUpgrade perfUpgrade kernel-develUpgrade python-perfUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-toolsUpgrade bpftoolUpgrade kernel-debuginfo-common-aarch64Upgrade kernel | May 20, 2026 | May 20, 2026 |
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-nvidia-tegra-5.15Upgrade linux-hwe-5.4Upgrade linux-gkeUpgrade linux-azure-5.15Upgrade linuxUpgrade linux-aws-fipsUpgrade linux-ibmUpgrade linux-iotUpgrade linux-aws-5.4Upgrade linux-gkeopUpgrade linux-azure-fipsUpgrade linux-azure-5.4Upgrade linux-gcp-5.4Upgrade linux-raspiUpgrade linux-hwe-5.15Upgrade linux-aws-5.15Upgrade linux-ibm-5.4Upgrade linux-azureUpgrade linux-lowlatencyUpgrade linux-oracle-5.15Upgrade linux-oracle-5.4Upgrade linux-intel-iotg-5.15Upgrade linux-realtimeUpgrade linux-gcpUpgrade linux-raspi-5.4Upgrade linux-gcp-fipsUpgrade linux-lowlatency-hwe-5.15Upgrade linux-awsUpgrade linux-kvmUpgrade linux-intel-iotgUpgrade linux-riscv-5.15Upgrade linux-nvidiaUpgrade linux-bluefieldUpgrade linux-gcp-5.15Upgrade linux-fipsUpgrade linux-oracleUpgrade linux-xilinx-zynqmpUpgrade linux-intel-iot-realtime | May 6, 2025 | May 1, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub