CVE-2020-36789

EUVD-2020-24230
In the Linux kernel, the following vulnerability has been resolved:

can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context

If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but
not always, the case), the 'WARN_ON(in_irq)' in
net/core/skbuff.c#skb_release_head_state() might be triggered, under network
congestion circumstances, together with the potential risk of a NULL pointer
dereference.

The root cause of this issue is the call to kfree_skb() instead of
dev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog().

This patch prevents the skb to be freed within the call to netif_rx() by
incrementing its reference count with skb_get(). The skb is finally freed by
one of the in-irq-context safe functions: dev_consume_skb_any() or
dev_kfree_skb_any(). The "any" version is used because some drivers might call
can_get_echo_skb() in a normal context.

The reason for this issue to occur is that initially, in the core network
stack, loopback skb were not supposed to be received in hardware IRQ context.
The CAN stack is an exeption.

This bug was previously reported back in 2017 in [1] but the proposed patch
never got accepted.

While [1] directly modifies net/core/dev.c, we try to propose here a
smoother modification local to CAN network stack (the assumption
behind is that only CAN devices are affected by this issue).

[1] http://lore.kernel.org/r/57a3ffb6-3309-3ad5-5a34-e93c3fe3614d@cetitec.com
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
2.6.31 ≤
𝑥
< 4.4.244
linuxlinux_kernel
4.5 ≤
𝑥
< 4.9.244
linuxlinux_kernel
4.10 ≤
𝑥
< 4.14.207
linuxlinux_kernel
4.15 ≤
𝑥
< 4.19.158
linuxlinux_kernel
4.20 ≤
𝑥
< 5.4.78
linuxlinux_kernel
5.5 ≤
𝑥
< 5.9.9
linuxlinux_kernel
5.10:rc1
linuxlinux_kernel
5.10:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.129-1
fixed
bookworm (security)
6.1.133-1
fixed
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.234-1
fixed
sid
6.12.22-1
fixed
trixie
6.12.21-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
trusty
needs-triage
xenial
needs-triage
linux-allwinner-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-aws
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
trusty
needs-triage
xenial
needs-triage
linux-aws-5.0
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-aws-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-aws-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-aws-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-aws-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-aws-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-aws-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-aws-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-aws-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-aws-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-aws-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-aws-fips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
linux-aws-hwe
focal
dne
jammy
dne
noble
dne
oracular
dne
xenial
needs-triage
linux-azure
bionic
ignored
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
trusty
needs-triage
xenial
needs-triage
linux-azure-4.15
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-azure-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-azure-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-azure-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-azure-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-azure-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-azure-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-azure-6.11
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-azure-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-azure-edge
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-azure-fde
focal
ignored
jammy
needs-triage
noble
dne
oracular
dne
linux-azure-fde-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-azure-fde-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-fde-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-azure-fips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
linux-azure-nvidia
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-bluefield
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-fips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
xenial
needs-triage
linux-gcp
bionic
ignored
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
xenial
needs-triage
linux-gcp-4.15
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-gcp-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gcp-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gcp-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-gcp-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-gcp-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-gcp-fips
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
linux-gke
focal
ignored
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-gke-4.15
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gke-5.15
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gke-5.4
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-gkeop
focal
ignored
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-gkeop-5.15
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-gkeop-5.4
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-hwe
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
xenial
needs-triage
linux-hwe-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-hwe-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-hwe-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-hwe-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-hwe-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-hwe-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-hwe-6.11
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-hwe-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-hwe-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-hwe-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-hwe-edge
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
xenial
ignored
linux-ibm
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-ibm-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-ibm-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-intel-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-intel-iot-realtime
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-intel-iotg
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-intel-iotg-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-iot
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-kvm
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne
xenial
needs-triage
linux-lowlatency
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
linux-lowlatency-hwe-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-lowlatency-hwe-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-lowlatency-hwe-6.11
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-lowlatency-hwe-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-lowlatency-hwe-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-lowlatency-hwe-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-lts-xenial
focal
dne
jammy
dne
noble
dne
oracular
dne
trusty
needs-triage
linux-nvidia
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-nvidia-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-nvidia-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-nvidia-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-nvidia-lowlatency
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-nvidia-tegra
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
dne
linux-nvidia-tegra-igx
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-oem
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-oem-5.10
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oem-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oem-5.14
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oem-5.17
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oem-5.6
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oem-6.0
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oem-6.1
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oem-6.11
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-oem-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oem-6.8
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-oracle
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
xenial
needs-triage
linux-oracle-5.0
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.13
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-oracle-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-oracle-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-oracle-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-raspi
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
linux-raspi-5.4
bionic
needs-triage
focal
dne
jammy
dne
noble
dne
oracular
dne
linux-raspi-realtime
focal
dne
jammy
dne
noble
needs-triage
oracular
dne
linux-raspi2
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-realtime
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
needs-triage
linux-riscv
focal
ignored
jammy
ignored
noble
needs-triage
oracular
needs-triage
linux-riscv-5.11
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-riscv-5.15
focal
needs-triage
jammy
dne
noble
dne
oracular
dne
linux-riscv-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-riscv-5.8
focal
ignored
jammy
dne
noble
dne
oracular
dne
linux-riscv-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-riscv-6.8
focal
dne
jammy
needs-triage
noble
dne
oracular
dne
linux-starfive-5.19
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-starfive-6.2
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-starfive-6.5
focal
dne
jammy
ignored
noble
dne
oracular
dne
linux-xilinx-zynqmp
focal
needs-triage
jammy
needs-triage
noble
dne
oracular
dne