VDB

DEBIAN-CVE-2024-44960

DEBIAN-CVE-2024-44960 PUBLISHED CVSS 5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: Check for unset descriptor Make sure the descriptor has been set before looking at maxpacket. This fixes a null pointer panic in this case. This may happen if the gadget doesn't properly set up the endpoint for the current speed, or the gadget descriptors are malformed and the descriptor for the speed/endpoint are not found. No current gadget driver is known to have this problem, but this may cause a hard-to-find bug during development of new gadgets.

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:11linux5.10.178-1, 5.10.179-4, 5.10.179-5
Debian:11linux-6.10, 6.1.106-3, 6.1.106-3
Debian:14linux0, 0
Debian:12linux6.1.69-1, 6.1.69-1~bpo11+1, 6.1.76-1
Debian:13linux0, 0

Timeline

  • Sep 4, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›