cbcvebase.
CVE-2024-26964
published 2024-05-01

CVE-2024-26964: In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Add error handling in xhci_map_urb_for_dma Currently xhci_map_urb_for_dma()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.2th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Add error handling in xhci_map_urb_for_dma Currently xhci_map_urb_for_dma() creates a temporary buffer and copies the SG list to the new linear buffer. But if the kzalloc_node() fails, then the following sg_pcopy_to_buffer() can lead to crash since it tries to memcpy to NULL pointer. So return -ENOMEM if kzalloc returns null pointer.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 2017a1e58472a27e532b9644b4a61dfe18f6baac < 4a49d24fdec0a802aa686a567a3989a9fdf4e5dd4a49d24fdec0a802aa686a567a3989a9fdf4e5dd
linuxlinux>= 2017a1e58472a27e532b9644b4a61dfe18f6baac < b2c898469dfc388f619c6c972a28466cbb1442eab2c898469dfc388f619c6c972a28466cbb1442ea
linuxlinux>= 2017a1e58472a27e532b9644b4a61dfe18f6baac < 620b6cf2f1a270f48d38e6b8ce199c1acb3e90f4620b6cf2f1a270f48d38e6b8ce199c1acb3e90f4
linuxlinux>= 2017a1e58472a27e532b9644b4a61dfe18f6baac < 962300a360d24c5be5a188cda48da58a37e4304d962300a360d24c5be5a188cda48da58a37e4304d
linuxlinux>= 2017a1e58472a27e532b9644b4a61dfe18f6baac < 7b6cc33593d7ccfc3011b290849cfa899db467577b6cc33593d7ccfc3011b290849cfa899db46757
linuxlinux>= 2017a1e58472a27e532b9644b4a61dfe18f6baac < be95cc6d71dfd0cba66e3621c65413321b398052be95cc6d71dfd0cba66e3621c65413321b398052
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.11 < 5.15.1545.15.154
linuxlinux_kernel>= 5.16 < 6.1.846.1.84
linuxlinux_kernel>= 6.2 < 6.6.246.6.24
linuxlinux_kernel>= 6.7 < 6.7.126.7.12
linuxlinux_kernel>= 6.8 < 6.8.36.8.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.