[PATCH] can: dev: drop CAN XL skbs when CAN XL mode is disabled

Cunhao Lu <[email protected]> Sat, 01 Aug 2026 17:29:56 +0800
Newsgroups org.kernel.vger.linux-can,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
Valid CAN XL skbs can be injected through AF_PACKET. Although
can_dropped_invalid_skb() verifies the CAN XL frame layout, it does not
check whether CAN XL is enabled on the target device.

can_dev_dropped_skb() already rejects CAN FD skbs when CAN FD is
disabled, but lacks the equivalent CAN XL check. Consequently, drivers
without CAN XL support may interpret a CAN XL skb as struct canfd_frame
or struct can_frame.

For example, rockchip_canfd interprets the mandatory CANXL_XLF flag at
offset 4 as struct canfd_frame.len. The resulting value is at least 128,
so the driver reads beyond the skb frame data and writes beyond the
controller TX data register window.

Reject CAN XL skbs in the common transmit validation helper unless
CAN_CTRLMODE_XL is enabled.

Fixes: fb08cba12b52 ("can: canxl: update CAN infrastructure for CAN XL frames")
Reported-by: Sashiko <[email protected]>
Closes: https://lore.kernel.org/linux-can/[email protected]/
Cc: [email protected]
Signed-off-by: Cunhao Lu <[email protected]>
---
 include/linux/can/dev.h | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/include/linux/can/dev.h b/include/linux/can/dev.h
index 6d0710d6f571..13fa607474b7 100644
--- a/include/linux/can/dev.h
+++ b/include/linux/can/dev.h
@@ -167,6 +167,11 @@ static inline bool can_dev_dropped_skb(struct net_device *dev, struct sk_buff *s
 		goto invalid_skb;
 	}
 
+	if (!(priv->ctrlmode & CAN_CTRLMODE_XL) && can_is_canxl_skb(skb)) {
+		netdev_info_once(dev, "CAN XL is disabled, dropping skb\n");
+		goto invalid_skb;
+	}
+
 	if (can_dev_in_xl_only_mode(priv) && !can_is_canxl_skb(skb)) {
 		netdev_info_once(dev,
 				 "Error signaling is disabled, dropping skb\n");

---
base-commit: 02dc699f83d04069fdabc996fc22d47cda47a4a9
change-id: 20260801-master-bc2e15d668f5

Best regards,
--  
Cunhao Lu <[email protected]>