Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-25741

Опубликовано: 12 фев. 2024
Источник: redhat
CVSS3: 5.5

Описание

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

A flaw was found in the f_printer driver in the Linux kernel. Due to an incorrect use of the USB Gadget API, the printer_write function in the drivers/usb/gadget/function/f_printer.c file can trigger a WARN_ON_ONCE in the usb_ep_queue function in the drivers/usb/gadget/udc/core.c file, resulting in a denial of service.

Отчет

The kernel as shipped by Red Hat Enterprise Linux 8 is not affected by this vulnerability because the f_printer and the USB Gadget driver/API is not enabled. In Red Hat Enterprise Linux 9, the f_printer driver is not enable as well, but the USB Gadget driver/API, where the WARN_ON_ONCE is triggered, is available in the aarch64 architecture.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-691
https://bugzilla.redhat.com/show_bug.cgi?id=2263884kernel: f_printer: crash leading to denial of service

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

CVSS3: 5.5
nvd
больше 2 лет назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

msrc
12 месяцев назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

CVSS3: 5.5
debian
больше 2 лет назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux ...

CVSS3: 5.5
github
больше 2 лет назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

5.5 Medium

CVSS3