CVE-2025-39986 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux
46 documents7 sources
Severity
7.8HIGHOSV
OSV5.5OSV3.2
No vectorEPSS
0.1%
top 78.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateApr 13
Description
In the Linux kernel, the following vulnerability has been resolved:
can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow
Sending an PF_PACKET allows to bypass the CAN framework logic and to
directly reach the xmit() function of a CAN driver. The only check
which is performed by the PF_PACKET framework is to make sure that
skb->len fits the interface's MTU.
Unfortunately, because the sun4i_can driver does not populate its
net_device_ops->ndo_change_mtu(), it is possible for an …
Affected Packages7 packages
▶CVEListV5linux/linux0738eff14d817a02ab082c392c96a1613006f158 — 063539db42203b29d5aa2adf0cae3d68c646a6b6+8