CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel affects the USB channel control index, which can lead to heap out-of-bounds reads due to insufficient bounds checking on the derived index. This flaw can result in kernel panic when triggered in the IRQ context, potentially causing system instability. Organizations using affected Linux systems, particularly those relying on USB interfaces for communication, should prioritize remediation to mitigate the risk of crashes and service disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: add bounds check for USB channel index The channel control index ctrl_idx is derived from rx->len which comes directly from a device USB payload. The mask 0x0f allows values 0-15, but the array size of usb_if->dev[] is only 2. Values 2-15 cause heap out-of-bounds read, eventually causing kernel panic in the IRQ context. Add bounds checking for ctrl_idx before the array access in both pcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error().