CVE-2022-48977: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: can: af_can: fix NULL pointer dereference in can_rcv_filter Analogue to commit 8aa59e355949 ("can: af_can: fix NULL pointer dereference in can_rx_register()") we need to check for a missing initialization of ml_priv in the receive path of CAN frames. Since commit 4e096a18867a ("net: introduce CAN specific pointer in the struct net_device") the check for dev->type to be ARPHRD_CAN is not sufficient anymore since bonding or tun netdevices claim to be CAN devices but do not initialize ml_priv accordingly.

Affected products

  • Linux Linux Kernel: from 5.4.110, before 5.4.227 (fixed in 5.4.227); from 5.10.28, before 5.10.159 (fixed in 5.10.159); from 5.11.12, before 5.15.83 (fixed in 5.15.83); from 5.16, before 6.0.13 (fixed in 6.0.13); version 6.1 only

Published 2024-10-21. Last modified 2026-06-17.