Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-25258

Опубликовано: 16 фев. 2022
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

A NULL pointer dereference flaw was found in the Linux kernel’s USB gadget subsystem in the way a user uses too many interfaces for the gadget type. This flaw allows a local user to crash the system.

Отчет

There was no shipped kernel version that was seen affected by this problem.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Virtualization 4kernelNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2055502kernel: security issues in the OS descriptor handling section of composite_setup function (composite.c)

EPSS

Процентиль: 18%
0.00058
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.6
ubuntu
больше 3 лет назад

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVSS3: 4.6
nvd
больше 3 лет назад

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVSS3: 4.6
debian
больше 3 лет назад

An issue was discovered in drivers/usb/gadget/composite.c in the Linux ...

CVSS3: 4.6
github
больше 3 лет назад

An issue was discovered in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

CVSS3: 7.8
fstec
больше 3 лет назад

Уязвимость драйвера drivers/usb/gadget/composite.c ядра операционной системы Linux, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 18%
0.00058
Низкий

4.6 Medium

CVSS3