« Volver al listado

CVE-2023-54039

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

can: j1939: j1939_tp_tx_dat_new(): fix out-of-bounds memory access

In the j1939_tp_tx_dat_new() function, an out-of-bounds memory access could occur during the memcpy() operation if the size of skb->cb is larger than the size of struct j1939_sk_buff_cb. This is because the memcpy() operation uses the size of skb->cb, leading to a read beyond the struct j1939_sk_buff_cb.

Updated the memcpy() operation to use the size of struct j1939_sk_buff_cb instead of the size of skb->cb. This ensures that the memcpy() operation only reads the memory within the bounds of struct j1939_sk_buff_cb, preventing out-of-bounds memory access.

Leer descripción completaMostrar menos

Additionally, add a BUILD_BUG_ON() to check that the size of skb->cb is greater than or equal to the size of struct j1939_sk_buff_cb. This ensures that the skb->cb buffer is large enough to hold the j1939_sk_buff_cb structure.

[mkl: rephrase commit message]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54039",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9d71dd0c70099914fcd063135da3c580865e924c",
              "lessThan": "d2136f05690c272dfc9f9d6efcc51d5f53494b33",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d71dd0c70099914fcd063135da3c580865e924c",
              "lessThan": "70caa596d158a5d84b117f722d58f3ea503a5ba9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d71dd0c70099914fcd063135da3c580865e924c",
              "lessThan": "4fe1d9b6231a68ffc91318f57fd8e4982f028cf7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d71dd0c70099914fcd063135da3c580865e924c",
              "lessThan": "4c3fb22a6ec68258ee129a2e6b720f43dffc562f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d71dd0c70099914fcd063135da3c580865e924c",
              "lessThan": "36befc9aed6202b4a9b906529aea13eacd7e34ff",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d71dd0c70099914fcd063135da3c580865e924c",
              "lessThan": "b45193cb4df556fe6251b285a5ce44046dd36b4a",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/can/j1939/transport.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.241",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.178",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.107",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.24",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2.11",
              "versionType": "semver",
              "lessThanOrEqual": "6.2.*"
            },
            {
              "status": "unaffected",
              "version": "6.3",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/can/j1939/transport.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-24T11:15:56.890",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/36befc9aed6202b4a9b906529aea13eacd7e34ff",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4c3fb22a6ec68258ee129a2e6b720f43dffc562f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4fe1d9b6231a68ffc91318f57fd8e4982f028cf7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/70caa596d158a5d84b117f722d58f3ea503a5ba9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b45193cb4df556fe6251b285a5ce44046dd36b4a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d2136f05690c272dfc9f9d6efcc51d5f53494b33",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: j1939_tp_tx_dat_new(): fix out-of-bounds memory access\n\nIn the j1939_tp_tx_dat_new() function, an out-of-bounds memory access\ncould occur during the memcpy() operation if the size of skb->cb is\nlarger than the size of struct j1939_sk_buff_cb. This is because the\nmemcpy() operation uses the size of skb->cb, leading to a read beyond\nthe struct j1939_sk_buff_cb.\n\nUpdated the memcpy() operation to use the size of struct\nj1939_sk_buff_cb instead of the size of skb->cb. This ensures that the\nmemcpy() operation only reads the memory within the bounds of struct\nj1939_sk_buff_cb, preventing out-of-bounds memory access.\n\nAdditionally, add a BUILD_BUG_ON() to check that the size of skb->cb\nis greater than or equal to the size of struct j1939_sk_buff_cb. This\nensures that the skb->cb buffer is large enough to hold the\nj1939_sk_buff_cb structure.\n\n[mkl: rephrase commit message]"
    }
  ],
  "lastModified": "2026-06-17T06:46:41.667",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}