In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: fix potential NULL pointer dereference on udev->serial The driver assumed that es58x_dev->udev->serial could never be NULL. While this is true on commercially available devices, an attacker could spoof the device identity providing a NULL USB serial number. That would trigger a NULL pointer dereference. Add a check on es58x_dev->udev->serial before accessing it.
Product | Vendor | Version |
---|---|---|
Linux | Linux | 5.0.x prior to 5.0.6; 4.3.x prior to 4.3.17 |
Linux | Linux | <= 20.004.30017 |