Executive brief
A security vulnerability exists in the Linux kernel driver for ETAS ES58X CAN USB interfaces, which are used for communication in automotive and industrial networks. A local attacker can bypass standard network protections to send specially crafted data packets that exceed the expected size. This can lead to a system crash or allow the attacker to gain unauthorized access to sensitive system memory, potentially compromising the entire device.
Technical details
A buffer overflow vulnerability exists in the etas_es58x CAN driver within the Linux kernel due to the absence of the ndo_change_mtu function in net_device_ops. This omission allows a local user with sufficient privileges to set an arbitrarily large MTU (e.g., 9999) on the CAN interface. By subsequently using a PF_PACKET socket with the ETH_P_CANXL protocol, an attacker can bypass CAN framework validation and inject malicious CAN XL frames into the driver's xmit function. The driver misinterprets these XL frames as standard CAN/CANFD frames, leading to an out-of-bounds write during a memcpy operation in functions like es581_4_tx_can_msg. The issue has been resolved by populating ndo_change_mtu with can_change_mtu to enforce proper MTU limits.
Affected products
- Linux Linux Kernel 5.13 to 5.15.194, 6.1.155, 6.6.109, 6.10.14, 6.11.3
Timeline
- 2025-09-18: patched: Initial patch authored
- 2025-10-15: disclosed: CVE published
References
- https://git.kernel.org/stable/c/38c0abad45b190a30d8284a37264d2127a6ec303
- https://git.kernel.org/stable/c/72de0facc50afdb101fb7197d880407f1abfc77f
- https://git.kernel.org/stable/c/b26cccd87dcddc47b450a40f3b1ac3fe346efcff
- https://git.kernel.org/stable/c/c4e582e686c4d683c87f2b4a316385b3d81d370f
- https://git.kernel.org/stable/c/cbc1de71766f326a44bb798aeae4a7ef4a081cc9
- https://git.kernel.org/stable/c/e587af2c89ecc6382c518febea52fa9ba81e47c0