<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 00:30:05 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-22003 — can: ucan: fix out of bound read in strscpy() source</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-22003</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: ucan: fix out of bound read in strscpy() source&lt;/p&gt;
&lt;p&gt;Commit 7fdaf8966aae (&amp;#34;can: ucan: use strscpy() to instead of strncpy()&amp;#34;)
unintentionally introduced a one byte out of bound read on strscpy()&amp;#39;s
source argument (which is kind of ironic knowing that strscpy() is meant
to be a more secure alternative :)).&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s consider below buffers:&lt;/p&gt;
&lt;p&gt;dest[len + 1]; /* will be NUL terminated */
  src[len]; /* may not be NUL terminated */&lt;/p&gt;
&lt;p&gt;When doing:&lt;/p&gt;
&lt;p&gt;strncpy(dest, src, len);
  dest[len] = &amp;#39;\0&amp;#39;;&lt;/p&gt;
&lt;p&gt;strncpy() will read up to len bytes from src.&lt;/p&gt;
&lt;p&gt;On the other hand:&lt;/p&gt;
&lt;p&gt;strscpy(dest, src, len + 1);&lt;/p&gt;
&lt;p&gt;will read up to len + 1 bytes from src, that is to say, an out of bound
read of one byte will occur on src if it is not NUL terminated. Note
that the src[len] byte is never copied, but strscpy() still needs to
read it to check whether a truncation occurred or not.&lt;/p&gt;
&lt;p&gt;This exact pattern happened in ucan.&lt;/p&gt;
&lt;p&gt;The root cause is that the source is not NUL terminated. Instead of
doing a copy in a local buffer, directly NUL terminate it as soon as
usb_control_msg() returns. With this, the local firmware_str[] variable
can be removed.&lt;/p&gt;
&lt;p&gt;On top of this do a couple refactors:&lt;/p&gt;
&lt;p&gt;- ucan_ctl_payload-&amp;gt;raw is only used for the firmware string, so
    rename it to ucan_ctl_payload-&amp;gt;fw_str and change its type from u8 to
    char.&lt;/p&gt;
&lt;p&gt;- ucan_device_request_in() is only used to retrieve the firmware
    string, so rename it to ucan_get_fw_str() and re…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;can: ucan: fix out of bound read in strscpy() source&lt;/p&gt;
&lt;p&gt;Commit 7fdaf8966aae (&amp;#34;can: ucan: use strscpy() to instead of strncpy()&amp;#34;)
unintentionally introduced a one byte out of bound read on strscpy()&amp;#39;s
source argument (which is kind of ironic knowing that strscpy() is meant
to be a more secure alternative :)).&lt;/p&gt;
&lt;p&gt;Let&amp;#39;s consider below buffers:&lt;/p&gt;
&lt;p&gt;dest[len + 1]; /* will be NUL terminated */
  src[len]; /* may not be NUL terminated */&lt;/p&gt;
&lt;p&gt;When doing:&lt;/p&gt;
&lt;p&gt;strncpy(dest, src, len);
  dest[len] = &amp;#39;\0&amp;#39;;&lt;/p&gt;
&lt;p&gt;strncpy() will read up to len bytes from src.&lt;/p&gt;
&lt;p&gt;On the other hand:&lt;/p&gt;
&lt;p&gt;strscpy(dest, src, len + 1);&lt;/p&gt;
&lt;p&gt;will read up to len + 1 bytes from src, that is to say, an out of bound
read of one byte will occur on src if it is not NUL terminated. Note
that the src[len] byte is never copied, but strscpy() still needs to
read it to check whether a truncation occurred or not.&lt;/p&gt;
&lt;p&gt;This exact pattern happened in ucan.&lt;/p&gt;
&lt;p&gt;The root cause is that the source is not NUL terminated. Instead of
doing a copy in a local buffer, directly NUL terminate it as soon as
usb_control_msg() returns. With this, the local firmware_str[] variable
can be removed.&lt;/p&gt;
&lt;p&gt;On top of this do a couple refactors:&lt;/p&gt;
&lt;p&gt;- ucan_ctl_payload-&amp;gt;raw is only used for the firmware string, so
    rename it to ucan_ctl_payload-&amp;gt;fw_str and change its type from u8 to
    char.&lt;/p&gt;
&lt;p&gt;- ucan_device_request_in() is only used to retrieve the firmware
    string, so rename it to ucan_get_fw_str() and re…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-22003</guid>
    </item>
  </channel>
</rss>
