Vulnerability identifier: #VU96852
Vulnerability risk: Low
CVSSv4.0: [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-476
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the xhci_configure_endpoint() and xhci_setup_device() functions in drivers/usb/host/xhci.c. A local user can perform a denial of service (DoS) attack.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
http://git.kernel.org/stable/c/ef0a0e616b2789bb804a0ce5e161db03170a85b6
http://git.kernel.org/stable/c/a57b0ebabe6862dce0a2e0f13e17941ad72fc56b
http://git.kernel.org/stable/c/0f0654318e25b2c185e245ba4a591e42fabb5e59
http://git.kernel.org/stable/c/365ef7c4277fdd781a695c3553fa157d622d805d
http://git.kernel.org/stable/c/5ad898ae82412f8a689d59829804bff2999dd0ea
http://git.kernel.org/stable/c/6b99de301d78e1f5249e57ef2c32e1dec3df2bb1
http://git.kernel.org/stable/c/8fb9d412ebe2f245f13481e4624b40e651570cbd
http://git.kernel.org/stable/c/af8e119f52e9c13e556be9e03f27957554a84656
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.