Wind River Support Network

HomeDefectsSCP7-958
Fixed

SCP7-958 : Security Advisory - linux - CVE-2019-3701

Created: Jan 15, 2019    Updated: May 21, 2019
Resolved Date: Apr 2, 2019
Found In Version: 7.0.0.30
Fix Version: 7.0.0.30
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Kernel

Description

An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. Because of a missing check, the CAN drivers may write arbitrary content beyond the data registers in the CAN controller's I/O memory when processing can-gw manipulated outgoing frames. This is related to cgw_csum_xor_rel. An unprivileged user can trigger a system crash (general protection fault).

https://nvd.nist.gov/vuln/detail/CVE-2019-3701
Live chat
Online