Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5c8p-jxw7-78rv

Опубликовано: 17 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.6

Описание

An issue was discovered in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

An issue was discovered in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

EPSS

Процентиль: 18%
0.00058
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 4.6
ubuntu
больше 3 лет назад

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVSS3: 4.6
redhat
больше 3 лет назад

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVSS3: 4.6
nvd
больше 3 лет назад

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVSS3: 4.6
debian
больше 3 лет назад

An issue was discovered in drivers/usb/gadget/composite.c in the Linux ...

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость драйвера drivers/usb/gadget/composite.c ядра операционной системы Linux, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 18%
0.00058
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-476