• CVE-2023-52887

发布时间: 2024年8月9日

修改时间: 2025年1月24日

概要

In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new This patch enhances error handling in scenarios with RTS (Request to Send) messages arriving closely. It replaces the less informative WARN_ON_ONCE backtraces with a new error handling method. This provides clearer error messages and allows for the early termination of problematic sessions. Previously, sessions were only released at the end of j1939_xtp_rx_rts(). Potentially this could be reproduced with something like: testj1939 -r vcan0:0x80 & while true; do # send first RTS cansend vcan0 18EC8090#1014000303002301; # send second RTS cansend vcan0 18EC8090#1014000303002301; # send abort cansend vcan0 18EC8090#ff00000000002301; done

CVSS v3 指标

NVD openEuler
Confidentiality Low
Attack Vector Adjacent
CVSS评分 N/A 4.6
Attack Complexity High
Privileges Required Low
Scope Unchanged
Integrity Low
User Interaction None
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-4973 kernel security update 2025年2月28日

影响产品

产品 状态
KY3.5.2 kernel Fixed
KY3.5.3 kernel Fixed
V6 kernel Fixed