CVE-2025-39873 (GCVE-0-2025-39873)
Vulnerability from cvelistv5
Published
2025-09-23 06:00
Modified
2026-08-05 12:05
Summary
In the Linux kernel, the following vulnerability has been resolved: can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB can_put_echo_skb() takes ownership of the SKB and it may be freed during or after the call. However, xilinx_can xcan_write_frame() keeps using SKB after the call. Fix that by only calling can_put_echo_skb() after the code is done touching the SKB. The tx_lock is held for the entire xcan_write_frame() execution and also on the can_get_echo_skb() side so the order of operations does not matter. An earlier fix commit 3d3c817c3a40 ("can: xilinx_can: Fix usage of skb memory") did not move the can_put_echo_skb() call far enough. [mkl: add "commit" in front of sha1 in patch description] [mkl: fix indention]
Impacted products
Vendor Product Version
Linux Linux Version: 1598efe57b3e768056e4ca56cb9cf33111e68d1c
Version: 1598efe57b3e768056e4ca56cb9cf33111e68d1c
Version: 1598efe57b3e768056e4ca56cb9cf33111e68d1c
Version: 1598efe57b3e768056e4ca56cb9cf33111e68d1c
Version: 1598efe57b3e768056e4ca56cb9cf33111e68d1c
Version: 1598efe57b3e768056e4ca56cb9cf33111e68d1c
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T17:44:20.103Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/can/xilinx_can.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "e202ffd9e54538ef67ec301ebd6d9da4823466c9",
              "status": "affected",
              "version": "1598efe57b3e768056e4ca56cb9cf33111e68d1c",
              "versionType": "git"
            },
            {
              "lessThan": "1139321161a3ba5e45e61e0738b37f42f20bc57a",
              "status": "affected",
              "version": "1598efe57b3e768056e4ca56cb9cf33111e68d1c",
              "versionType": "git"
            },
            {
              "lessThan": "94b050726288a56a6b8ff55aa641f2fedbd3b44c",
              "status": "affected",
              "version": "1598efe57b3e768056e4ca56cb9cf33111e68d1c",
              "versionType": "git"
            },
            {
              "lessThan": "725b33deebd6e4c96fe7893f384510a54258f28f",
              "status": "affected",
              "version": "1598efe57b3e768056e4ca56cb9cf33111e68d1c",
              "versionType": "git"
            },
            {
              "lessThan": "668cc1e3bb21101d074e430de1b7ba8fd10189e7",
              "status": "affected",
              "version": "1598efe57b3e768056e4ca56cb9cf33111e68d1c",
              "versionType": "git"
            },
            {
              "lessThan": "ef79f00be72bd81d2e1e6f060d83cf7e425deee4",
              "status": "affected",
              "version": "1598efe57b3e768056e4ca56cb9cf33111e68d1c",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/can/xilinx_can.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "lessThan": "4.19",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.194",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.153",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.107",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.48",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.16.*",
              "status": "unaffected",
              "version": "6.16.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.17",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.194",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.153",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.107",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.48",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16.8",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.17",
                  "versionStartIncluding": "4.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB\n\ncan_put_echo_skb() takes ownership of the SKB and it may be freed\nduring or after the call.\n\nHowever, xilinx_can xcan_write_frame() keeps using SKB after the call.\n\nFix that by only calling can_put_echo_skb() after the code is done\ntouching the SKB.\n\nThe tx_lock is held for the entire xcan_write_frame() execution and\nalso on the can_get_echo_skb() side so the order of operations does not\nmatter.\n\nAn earlier fix commit 3d3c817c3a40 (\"can: xilinx_can: Fix usage of skb\nmemory\") did not move the can_put_echo_skb() call far enough.\n\n[mkl: add \"commit\" in front of sha1 in patch description]\n[mkl: fix indention]"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is only reached from `ndo_start_xmit` on the xilinx_can device, i.e. by a local process transmitting a frame through a `PF_CAN` socket (`sendmsg()`); received bus traffic does not enter this path. Exploitation therefore requires local system access.\nAC:L - The attacker drives both the transmission and the conditions that make `can_put_echo_skb()` free the SKB (TX flooding to saturate the FIFO/echo slots, memory pressure to fail the `GFP_ATOMIC` `skb_clone`), and can retry indefinitely at line rate; the free is not a race the attacker cannot influence.\nPR:L - `can_create()` in net/can/af_can.c and the CAN_RAW protocol perform no capability check, so any unprivileged local user can open a raw CAN socket, bind it to the interface and transmit. No root or CAP_NET_ADMIN is needed to reach `xcan_write_frame()`.\nUI:N - The attacker\u0027s own `sendmsg()` call drives the whole path; no victim action or cooperation is required.\nS:U - The corruption stays within the kernel\u0027s own security authority \u2014 freed kernel heap and the driver\u0027s MMIO window \u2014 with no crossing of a hypervisor, IOMMU or sandbox boundary.\nC:H - The UAF reads freed (and, with a groomed `cf-\u003elen`, out-of-bounds) kernel heap contents and writes them into the CAN controller\u0027s TX registers, which are then transmitted on the physical CAN bus where any node \u2014 including the attacker\u0027s \u2014 can read them, giving direct kernel memory disclosure.\nI:H - `cf-\u003elen` read from reclaimed memory is unbounded (up to 255), so the write loop overruns the mailbox\u0027s data window and writes attacker-influenced dwords into adjacent CAN controller registers, and a UAF of this kind is generally leverageable into heap-spray-based write primitives; it also injects arbitrary frame content onto a safety-critical bus.\nA:H - The use-after-free triggers a KASAN panic on hardened kernels, and the out-of-bounds register writes plus lost echo-SKB accounting corrupt controller state and permanently wedge the TX queue (`netif_stop_queue()` with no matching completion), producing a crash or denial of CAN service."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:05:49.898Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e202ffd9e54538ef67ec301ebd6d9da4823466c9"
        },
        {
          "url": "https://git.kernel.org/stable/c/1139321161a3ba5e45e61e0738b37f42f20bc57a"
        },
        {
          "url": "https://git.kernel.org/stable/c/94b050726288a56a6b8ff55aa641f2fedbd3b44c"
        },
        {
          "url": "https://git.kernel.org/stable/c/725b33deebd6e4c96fe7893f384510a54258f28f"
        },
        {
          "url": "https://git.kernel.org/stable/c/668cc1e3bb21101d074e430de1b7ba8fd10189e7"
        },
        {
          "url": "https://git.kernel.org/stable/c/ef79f00be72bd81d2e1e6f060d83cf7e425deee4"
        }
      ],
      "title": "can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-39873",
    "datePublished": "2025-09-23T06:00:46.157Z",
    "dateReserved": "2025-04-16T07:20:57.144Z",
    "dateUpdated": "2026-08-05T12:05:49.898Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…