A flaw in the Linux kernel CAN networking receive path, tracked as CVE-2023-2166, can allow a local low-privileged user to crash an affected system. The defect occurs when can_rcv_filter handles received CAN frames and dereferences the CAN-specific ml_priv pointer without confirming it was initialized, resulting in a NULL-pointer dereference and denial of service.
The condition can arise because bonding or TUN network devices may report the CAN hardware type (ARPHRD_CAN) without initializing ml_priv; the issue was reported by syzbot and Wei Chen and fixed upstream by adding the required initialization check. Red Hat rates the issue CVSS 5.5 (Moderate), with availability impact only, and released corrected kernel packages for affected Red Hat Enterprise Linux 8 and 9 systems in errata including RHSA-2024:0461, RHSA-2024:0881, and RHSA-2024:0897.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:0881 for RHEL 8 kernel-rt and RHSA-2024:0897 for the RHEL 8 kernel, addressing CVE-2023-2166.
Red Hat released RHSA-2024:0724 to fix CVE-2023-2166 for the Red Hat Enterprise Linux 8.6 Extended Update Support kernel.
Red Hat released RHSA-2024:0461 to fix CVE-2023-2166 for the Red Hat Enterprise Linux 9 kernel.
Linux upstream commit 0acc442309a0a1b01bcdaa135e56e6398a49439c added validation for the CAN-specific ml_priv pointer in the CAN receive path. The flaw could be triggered by bonding or TUN devices reporting ARPHRD_CAN without initializing ml_priv.
Red Hat released RHSA-2024:3528 to fix CVE-2023-2166 in the Red Hat Enterprise Linux 8.2 Advanced Update Support kernel.
Red Hat issued RHSA-2024:1367 for RHEL 8.4 Advanced Mission Critical Update Support, RHSA-2024:1382 for RHEL 8.4 Telecommunications Update Service kernel-rt, and RHSA-2024:1404 for RHEL 8.8 Extended Update Support, fixing CVE-2023-2166.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.