Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-25741

Опубликовано: 12 фев. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

A flaw was found in the f_printer driver in the Linux kernel. Due to an incorrect use of the USB Gadget API, the printer_write function in the drivers/usb/gadget/function/f_printer.c file can trigger a WARN_ON_ONCE in the usb_ep_queue function in the drivers/usb/gadget/udc/core.c file, resulting in a denial of service.

Отчет

The kernel as shipped by Red Hat Enterprise Linux 8 is not affected by this vulnerability because the f_printer and the USB Gadget driver/API is not enabled. In Red Hat Enterprise Linux 9, the f_printer driver is not enable as well, but the USB Gadget driver/API, where the WARN_ON_ONCE is triggered, is available in the aarch64 architecture.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-691
https://bugzilla.redhat.com/show_bug.cgi?id=2263884kernel: f_printer: crash leading to denial of service

EPSS

Процентиль: 0%
0.00007
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 2 года назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

CVSS3: 5.5
nvd
почти 2 года назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

CVSS3: 5.5
debian
почти 2 года назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux ...

CVSS3: 5.5
github
почти 2 года назад

printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.

CVSS3: 5.5
fstec
почти 4 года назад

Уязвимость функции printer_write компонента drivers/usb/gadget/function/f_printer.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 0%
0.00007
Низкий

5.5 Medium

CVSS3