Wind River Support Network

HomeDefectsLIN1018-3399
Fixed

LIN1018-3399 : Security Advisory - linux - CVE-2019-3701

Created: Jan 15, 2019    Updated: May 21, 2019
Resolved Date: Jan 31, 2019
Found In Version: unknown
Fix Version: 10.18.44.4
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Kernel

Description

An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. Because of a missing check, the CAN drivers may write arbitrary content beyond the data registers in the CAN controller's I/O memory when processing can-gw manipulated outgoing frames. This is related to cgw_csum_xor_rel. An unprivileged user can trigger a system crash (general protection fault).

https://nvd.nist.gov/vuln/detail/CVE-2019-3701

CVEs


Live chat
Online