{"id":"DEBIAN-CVE-2022-48830","details":"In the Linux kernel, the following vulnerability has been resolved:  can: isotp: fix potential CAN frame reception race in isotp_rcv()  When receiving a CAN frame the current code logic does not consider concurrently receiving processes which do not show up in real world usage.  Ziyang Xuan writes:  The following syz problem is one of the scenarios. so-\u003erx.len is changed by isotp_rcv_ff() during isotp_rcv_cf(), so-\u003erx.len equals 0 before alloc_skb() and equals 4096 after alloc_skb(). That will trigger skb_over_panic() in skb_put().  ======================================================= CPU: 1 PID: 19 Comm: ksoftirqd/1 Not tainted 5.16.0-rc8-syzkaller #0 RIP: 0010:skb_panic+0x16c/0x16e net/core/skbuff.c:113 Call Trace:  \u003cTASK\u003e  skb_over_panic net/core/skbuff.c:118 [inline]  skb_put.cold+0x24/0x24 net/core/skbuff.c:1990  isotp_rcv_cf net/can/isotp.c:570 [inline]  isotp_rcv+0xa38/0x1e30 net/can/isotp.c:668  deliver net/can/af_can.c:574 [inline]  can_rcv_filter+0x445/0x8d0 net/can/af_can.c:635  can_receive+0x31d/0x580 net/can/af_can.c:665  can_rcv+0x120/0x1c0 net/can/af_can.c:696  __netif_receive_skb_one_core+0x114/0x180 net/core/dev.c:5465  __netif_receive_skb+0x24/0x1b0 net/core/dev.c:5579  Therefore we make sure the state changes and data structures stay consistent at CAN frame reception time by adding a spin_lock in isotp_rcv(). This fixes the issue reported by syzkaller but does not affect real world operation.","modified":"2026-09-01T16:05:29.144915948Z","published":"2024-07-16T12:15:06.613Z","upstream":["CVE-2022-48830"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-48830"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48830.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48830.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.16.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-48830.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}