Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-54105— can: isotp: check CAN address family in isotp_bind()

AI Predicted 3.7 Difficulty: Easy EPSS 0.18% · P8

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinuxe057dd3fc20ffb3d7f150af46542a51b59b90127< de3c02383aa678f6799402ac47fdd89cf4bfcaa9affected
e057dd3fc20ffb3d7f150af46542a51b59b90127< 2fc6f337257f4f7c21ecff429241f7acaa6df4e8affected
e057dd3fc20ffb3d7f150af46542a51b59b90127< 9427584c2f153d0677ef3bad6f44028c60d728c4affected
e057dd3fc20ffb3d7f150af46542a51b59b90127< dd4faace51e41a82a8c0770ee0cc26088f9d9d06affected
e057dd3fc20ffb3d7f150af46542a51b59b90127< c6adf659a8ba85913e16a571d5a9bcd17d3d1234affected
5.10affected
< 5.10unaffected
5.10.200≤ 5.10.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-54105

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
can: isotp: check CAN address family in isotp_bind()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: can: isotp: check CAN address family in isotp_bind() Add missing check to block non-AF_CAN binds. Syzbot created some code which matched the right sockaddr struct size but used AF_XDP (0x2C) instead of AF_CAN (0x1D) in the address family field: bind$xdp(r2, &(0x7f0000000540)={0x2c, 0x0, r4, 0x0, r2}, 0x10) ^^^^ This has no funtional impact but the userspace should be notified about the wrong address family field content.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于isotp_bind函数缺少地址族检查,可能导致绑定错误。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux e057dd3fc20ffb3d7f150af46542a51b59b90127 ~ de3c02383aa678f6799402ac47fdd89cf4bfcaa9 -
LinuxLinux 5.10 -

II. Public POCs for CVE-2023-54105

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-54105

登录查看更多情报信息。

Other References for CVE-2023-54105 (4)

Same Patch Batch · Linux · 2025-12-24 · 322 CVEs total

CVE-2025-687459.8 CRITICALscsi: qla2xxx: Clear cmds after chip reset
CVE-2025-683599.8 CRITICALbtrfs: fix double free of qgroup record after failure to add delayed ref head
CVE-2025-687419.8 CRITICALscsi: qla2xxx: Fix improper freeing of purex item
CVE-2025-687269.8 CRITICALcrypto: aead - Fix reqsize handling
CVE-2025-687368.8 HIGHlandlock: Fix handling of disconnected directories
CVE-2025-683608.2 HIGHwifi: mt76: wed: use proper wed reference in mt76 wed driver callabacks
CVE-2025-683658.2 HIGHfs/ntfs3: Initialize allocated memory before use
CVE-2025-687357.8 HIGHdrm/panthor: Prevent potential UAF in group creation
CVE-2025-687307.8 HIGHaccel/ivpu: Fix page fault in ivpu_bo_unbind_all_bos_from_context()
CVE-2025-683707.8 HIGHcoresight: tmc: add the handle of the event to the path
CVE-2025-683797.8 HIGHRDMA/rxe: Fix null deref on srq->rq.queue after resize failure
CVE-2025-687247.8 HIGHcrypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
CVE-2025-683527.8 HIGHspi: ch341: fix out-of-bounds memory access in ch341_transfer_one
CVE-2025-687487.8 HIGHdrm/panthor: Fix UAF race between device unplug and FW event processing
CVE-2025-687477.8 HIGHdrm/panthor: Fix UAF on kernel BO VA nodes
CVE-2025-687497.8 HIGHaccel/ivpu: Fix race condition when unbinding BOs
CVE-2025-683477.8 HIGHALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events
CVE-2025-687467.8 HIGHspi: tegra210-quad: Fix timeout handling
CVE-2025-683497.5 HIGHNFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
CVE-2025-683697.5 HIGHntfs3: init run lock for extend inode

Showing top 20 of 322 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-54105

No comments yet


Leave a comment