CVE-2022-49845

Source
https://cve.org/CVERecord?id=CVE-2022-49845
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49845.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-49845
Downstream
Related
Published
2025-05-01T14:09:59.718Z
Modified
2026-04-11T12:44:36.194537Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
can: j1939: j1939_send_one(): fix missing CAN header initialization
Details

In the Linux kernel, the following vulnerability has been resolved:

can: j1939: j1939sendone(): fix missing CAN header initialization

The read access to struct canxlframe::len inside of a j1939 created skbuff revealed a missing initialization of reserved and later filled elements in struct canframe.

This patch initializes the 8 byte CAN header with zero.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/49xxx/CVE-2022-49845.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9d71dd0c70099914fcd063135da3c580865e924c
Fixed
d0513b095e1ef1469718564dec3fb3348556d0a8
Fixed
f8e0edeaa0f2b860bdbbf0aafb4492533043d650
Fixed
69e86c6268d59ceddd0abe9ae8f1f5296f316c3c
Fixed
2719f82ad5d8199cf5f346ea8bb3998ad5323b72
Fixed
3eb3d283e8579a22b81dd2ac3987b77465b2a22f

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49845.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.4.0
Fixed
5.4.225
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.155
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.79
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-49845.json"