Junglewise Threat Intelligence

CVE-2025-39988: Linux Kernel etas_es58x buffer overflow via MTU manipulation

CVE-2025-39988 · Severity: high · CVSS 7.8 · Published 2025-10-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability exists in the Linux kernel driver for ETAS ES58X CAN USB interfaces, which are used for communication in automotive and industrial networks. A local attacker can bypass standard network protections to send specially crafted data packets that exceed the expected size. This can lead to a system crash or allow the attacker to gain unauthorized access to sensitive system memory, potentially compromising the entire device.

Technical details

A buffer overflow vulnerability exists in the etas_es58x CAN driver within the Linux kernel due to the absence of the ndo_change_mtu function in net_device_ops. This omission allows a local user with sufficient privileges to set an arbitrarily large MTU (e.g., 9999) on the CAN interface. By subsequently using a PF_PACKET socket with the ETH_P_CANXL protocol, an attacker can bypass CAN framework validation and inject malicious CAN XL frames into the driver's xmit function. The driver misinterprets these XL frames as standard CAN/CANFD frames, leading to an out-of-bounds write during a memcpy operation in functions like es581_4_tx_can_msg. The issue has been resolved by populating ndo_change_mtu with can_change_mtu to enforce proper MTU limits.

Affected products

  • Linux Linux Kernel 5.13 to 5.15.194, 6.1.155, 6.6.109, 6.10.14, 6.11.3

Timeline

  • 2025-09-18: patched: Initial patch authored
  • 2025-10-15: disclosed: CVE published

References

Related threats