In the Linux kernel, the following vulnerability has been resolved: can: af_can: fix NULL pointer dereference in can_rcv_filter Analogue to commit 8aa59e355949 ("can: af_can: fix NULL pointer dereference in can_rx_register()") we need to check for a missing initialization of ml_priv in the receive path of CAN frames. Since commit 4e096a18867a ("net: introduce CAN specific pointer in the struct net_device") the check for dev->type to be ARPHRD_CAN is not sufficient anymore since bonding or tun netdevices claim to be CAN devices but do not initialize ml_priv accordingly.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 9.0.0.29935 |
| Linux | Linux | n/a |
| Linux | Linux | Version 1803 for ARM64-based Systems |
| Linux | Linux | n/a |