In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_tx_handler(): fix use after free of skb can_put_echo_skb() will clone skb then free the skb. Move the can_put_echo_skb() for the m_can version 3.0.x directly before the start of the xmit in hardware, similar to the 3.1.x branch.
Update Linux/Linux to d93ed9aff64968f4cdad690712eb4f48ae537bde if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scancan: m_can: m_can_tx_handler(): fix use after free of skb affects Linux/Linux (generic), Linux/Linux (generic). Severity is unknown. In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_tx_handler(): fix use after free of skb can_put_echo_skb() will clone skb then free the skb. Move the can_put_echo_skb() for the m_can version 3.0.x directly before the start of the xmit in hardware, similar to the 3.1.x branch.
AI coding agents often install or upgrade packages automatically in generic. A unknown vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=80646733f11c2e9de3b6339f7e635047e6087280 <d93ed9aff64968f4cdad690712eb4f48ae537bde || >=80646733f11c2e9de3b6339f7e635047e6087280 <d3892a747ab16b1eb6593a19d29f62c3b3f020ac || >=80646733f11c2e9de3b6339f7e635047e6087280 <7728d937ec403a1ceff9483023252d2cb8777f81 || >=80646733f11c2e9de3b6339f7e635047e6087280 <08d90846e438ac22dc56fc49ec0b0d195831c5ed || >=80646733f11c2e9de3b6339f7e635047e6087280 <869016a2938ac44f7b2fb7fc22c89edad99eb9b3 || >=80646733f11c2e9de3b6339f7e635047e6087280 <f43e64076ff1b1dcb893fb77ad1204105f710a29 || >=80646733f11c2e9de3b6339f7e635047e6087280 <4db7d6f481990dd179a9ee7126dc7aa31ea4fff3 || >=80646733f11c2e9de3b6339f7e635047e6087280 <31417073493f302d26ab66b3abc098d43227b835 || >=80646733f11c2e9de3b6339f7e635047e6087280 <2e8e79c416aae1de224c0f1860f2e3350fa171f8 |
In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_tx_handler(): fix use after free of skb can_put_echo_skb() will clone skb then free the skb. Move the can_put_echo_skb() for the m_can version 3.0.x directly before the start of the xmit in hardware, similar to the 3.1.x branch.
Update Linux/Linux to d93ed9aff64968f4cdad690712eb4f48ae537bde if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scancan: m_can: m_can_tx_handler(): fix use after free of skb affects Linux/Linux (generic), Linux/Linux (generic). Severity is unknown. In the Linux kernel, the following vulnerability has been resolved: can: m_can: m_can_tx_handler(): fix use after free of skb can_put_echo_skb() will clone skb then free the skb. Move the can_put_echo_skb() for the m_can version 3.0.x directly before the start of the xmit in hardware, similar to the 3.1.x branch.
AI coding agents often install or upgrade packages automatically in generic. A unknown vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=80646733f11c2e9de3b6339f7e635047e6087280 <d93ed9aff64968f4cdad690712eb4f48ae537bde || >=80646733f11c2e9de3b6339f7e635047e6087280 <d3892a747ab16b1eb6593a19d29f62c3b3f020ac || >=80646733f11c2e9de3b6339f7e635047e6087280 <7728d937ec403a1ceff9483023252d2cb8777f81 || >=80646733f11c2e9de3b6339f7e635047e6087280 <08d90846e438ac22dc56fc49ec0b0d195831c5ed || >=80646733f11c2e9de3b6339f7e635047e6087280 <869016a2938ac44f7b2fb7fc22c89edad99eb9b3 || >=80646733f11c2e9de3b6339f7e635047e6087280 <f43e64076ff1b1dcb893fb77ad1204105f710a29 || >=80646733f11c2e9de3b6339f7e635047e6087280 <4db7d6f481990dd179a9ee7126dc7aa31ea4fff3 || >=80646733f11c2e9de3b6339f7e635047e6087280 <31417073493f302d26ab66b3abc098d43227b835 || >=80646733f11c2e9de3b6339f7e635047e6087280 <2e8e79c416aae1de224c0f1860f2e3350fa171f8 |
| d93ed9aff64968f4cdad690712eb4f48ae537bde, d3892a747ab16b1eb6593a19d29f62c3b3f020ac, 7728d937ec403a1ceff9483023252d2cb8777f81, 08d90846e438ac22dc56fc49ec0b0d195831c5ed, 869016a2938ac44f7b2fb7fc22c89edad99eb9b3, f43e64076ff1b1dcb893fb77ad1204105f710a29, 4db7d6f481990dd179a9ee7126dc7aa31ea4fff3, 31417073493f302d26ab66b3abc098d43227b835, 2e8e79c416aae1de224c0f1860f2e3350fa171f8 |
| Linux/Linuxgeneric | 3.18 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| d93ed9aff64968f4cdad690712eb4f48ae537bde, d3892a747ab16b1eb6593a19d29f62c3b3f020ac, 7728d937ec403a1ceff9483023252d2cb8777f81, 08d90846e438ac22dc56fc49ec0b0d195831c5ed, 869016a2938ac44f7b2fb7fc22c89edad99eb9b3, f43e64076ff1b1dcb893fb77ad1204105f710a29, 4db7d6f481990dd179a9ee7126dc7aa31ea4fff3, 31417073493f302d26ab66b3abc098d43227b835, 2e8e79c416aae1de224c0f1860f2e3350fa171f8 |
| Linux/Linuxgeneric | 3.18 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard