nuttx/drivers/can
Catalin Visinescu ca73f0e9e5 drivers/can/ctucanfd_pci: Stack Overflow When Malformed CAN Data Is Received
A malformed packet can trigger memory corruption in the kernel leading to a
system crash or potentially arbitrary code execution in the kernel.

The CAN driver for the CTU CAN FD IP Core connected to the NuttX device
via a PCI / PCI Express (PCIe) bus shows a lack of consideration for
malformed data, assuming the CAN frames are always correct.

Ensure `frame->fmt.rwcnt` is 21 or less before it is used in the `for` loop.

A similar change was done in ctucanfd_sock_recv().

Tested locally, builds fine.

Signed-off-by: Catalin Visinescu <catalin_visinescu@yahoo.com>
2026-06-15 12:34:54 +02:00
..
can.c drivers/can: Fix close drain, write-only reader lifecycle, and STM32 RX header 2026-04-28 10:32:56 -03:00
can_common.c drivers/can: move CAN utils to CAN common files 2025-05-14 10:30:25 -03:00
can_sender.c drivers/can: repair compiler error 2026-01-16 01:37:50 +08:00
CMakeLists.txt drivers/can: move CAN utils to CAN common files 2025-05-14 10:30:25 -03:00
ctucanfd.h ctucanfd: increase rwcnt bitfield width and fix structure alignment 2026-01-17 12:43:48 +01:00
ctucanfd_pci.c drivers/can/ctucanfd_pci: Stack Overflow When Malformed CAN Data Is Received 2026-06-15 12:34:54 +02:00
Kconfig can: strict TX priority ordering to avoid priority inversion 2026-01-06 16:03:14 +08:00
kvaser_pci.c include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
Make.defs drivers/can: move CAN utils to CAN common files 2025-05-14 10:30:25 -03:00
mcp2515.c include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
mcp2515.h drivers: migrate to SPDX identifier 2024-11-06 18:02:25 +08:00
sja1000.c include/debug.h: Move to include/nuttx/debug.h 2026-04-07 07:50:06 -03:00
sja1000.h drivers/can: add Kvaser PCI card driver (qemu only) 2024-12-13 11:19:22 +08:00