CVE-2023-54039
Published: Dec 24, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_tp_tx_dat_new(): fix out-of-bounds memory access In the j1939_tp_tx_dat_new() function, an out-of-bounds memory access could occur during the memcpy() operation if the size of skb->cb is larger than the size of struct j1939_sk_buff_cb. This is because the memcpy() operation uses the size of skb->cb, leading to a read beyond the struct j1939_sk_buff_cb. Updated the memcpy() operation to use the size of struct j1939_sk_buff_cb instead of the size of skb->cb. This ensures that the memcpy() operation only reads the memory within the bounds of struct j1939_sk_buff_cb, preventing out-of-bounds memory access. Additionally, add a BUILD_BUG_ON() to check that the size of skb->cb is greater than or equal to the size of struct j1939_sk_buff_cb. This ensures that the skb->cb buffer is large enough to hold the j1939_sk_buff_cb structure. [mkl: rephrase commit message]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 9d71dd0c70099914fcd063135da3c580865e924c - < d2136f05690c272dfc9f9d6efcc51d5f53494b33affected 9d71dd0c70099914fcd063135da3c580865e924c - < 70caa596d158a5d84b117f722d58f3ea503a5ba9affected 9d71dd0c70099914fcd063135da3c580865e924c - < 4fe1d9b6231a68ffc91318f57fd8e4982f028cf7affected 9d71dd0c70099914fcd063135da3c580865e924c - < 4c3fb22a6ec68258ee129a2e6b720f43dffc562faffected 9d71dd0c70099914fcd063135da3c580865e924c - < 36befc9aed6202b4a9b906529aea13eacd7e34ff+1 more versions |
Linux | Linux | affected 5.4unaffected 0 - < 5.4unaffected 5.4.241 - <= 5.4.*unaffected 5.10.178 - <= 5.10.*unaffected 5.15.107 - <= 5.15.*+3 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now