DEBIAN-CVE-2022-49659

Source
https://security-tracker.debian.org/tracker/CVE-2022-49659
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49659.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2022-49659
Upstream
Published
2025-02-26T07:01:40Z
Modified
2025-09-25T03:18:48.263041Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved: can: mcan: mcan{readfifo,echotxevent}(): shift timestamp to full 32 bits In commit 1be37d3b0414 ("can: mcan: fix periph RX path: use rx-offload to ensure skbs are sent from softirq context") the RX path for peripheral devices was switched to RX-offload. Received CAN frames are pushed to RX-offload together with a timestamp. RX-offload is designed to handle overflows of the timestamp correctly, if 32 bit timestamps are provided. The timestamps of mcan core are only 16 bits wide. So this patch shifts them to full 32 bit before passing them to RX-offload.

References

Affected packages

Debian:12 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.18.14-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.18.14-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / linux

Package

Name
linux
Purl
pkg:deb/debian/linux?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.18.14-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}