[PATCH can-next 10/10] can: gs_usb: gs_usb_get_minimum_rx_length(): enforce data_length of 8 bytes for CAN error frames

From: Marc Kleine-Budde

Date: Sat Oct 03 2026 - 18:54:56 EST


By definition, CAN error frames have a length of CAN_ERR_DLC (= 8) bytes.
The gs_update_state() function accesses the data from CAN error frames;
therefore, for error frames increase the value of data_length in
gs_usb_get_minimum_rx_length() to CAN_ERR_DLC.

Signed-off-by: Marc Kleine-Budde <mkl@xxxxxxxxxxxxxx>
---
drivers/net/can/usb/gs_usb.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/drivers/net/can/usb/gs_usb.c b/drivers/net/can/usb/gs_usb.c
index 3c0464edb5d3..9ec6fed45b81 100644
--- a/drivers/net/can/usb/gs_usb.c
+++ b/drivers/net/can/usb/gs_usb.c
@@ -576,8 +576,12 @@ gs_usb_get_minimum_rx_length(const struct gs_can *dev, const struct gs_host_fram
minimum_length = sizeof(hf->header) + data_length;
} else {
if (hf->echo_id == GS_HOST_FRAME_ECHO_ID_RX &&
- !(hf->can_id & cpu_to_le32(CAN_RTR_FLAG)))
- data_length = can_cc_dlc2len(hf->can_dlc);
+ !(hf->can_id & cpu_to_le32(CAN_RTR_FLAG))) {
+ if (hf->can_id & cpu_to_le32(CAN_ERR_FLAG))
+ data_length = CAN_ERR_DLC;
+ else
+ data_length = can_cc_dlc2len(hf->can_dlc);
+ }

if (dev->feature & GS_CAN_FEATURE_HW_TIMESTAMP)
/* timestamp follows data field of max size */

--
2.53.0