cbcvebase.
CVE-2024-44960
published 2024-09-04

CVE-2024-44960: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: Check for unset descriptor Make sure the descriptor has been set before…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: core: Check for unset descriptor Make sure the descriptor has been set before looking at maxpacket. This fixes a null pointer panic in this case. This may happen if the gadget doesn't properly set up the endpoint for the current speed, or the gadget descriptors are malformed and the descriptor for the speed/endpoint are not found. No current gadget driver is known to have this problem, but this may cause a hard-to-find bug during development of new gadgets.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.16.80 < 3.173.17
linuxlinux>= 4.14.152 < 4.154.15
linuxlinux>= 4.19.82 < 4.19.3204.19.320
linuxlinux>= 4.4.199 < 4.54.5
linuxlinux>= 4.9.199 < 4.104.10
linuxlinux>= 5.3.9 < 5.45.4
linuxlinux>= 54f83b8c8ea9b22082a496deadf90447a326954e < df8e734ae5e605348aa0ca2498aedb73e815f244df8e734ae5e605348aa0ca2498aedb73e815f244
linuxlinux>= 54f83b8c8ea9b22082a496deadf90447a326954e < 7cc9ebcfe58be22f18056ad8bc6272d120bdcb3e7cc9ebcfe58be22f18056ad8bc6272d120bdcb3e
linuxlinux>= 54f83b8c8ea9b22082a496deadf90447a326954e < 50c5248b0ea8aae0529fdf28dac42a41312d3b6250c5248b0ea8aae0529fdf28dac42a41312d3b62
linuxlinux>= 54f83b8c8ea9b22082a496deadf90447a326954e < a0362cd6e503278add954123957fd47990e8d9bfa0362cd6e503278add954123957fd47990e8d9bf
linuxlinux>= 54f83b8c8ea9b22082a496deadf90447a326954e < 1a9df57d57452b104c46c918569143cf21d7ebf11a9df57d57452b104c46c918569143cf21d7ebf1
linuxlinux>= 54f83b8c8ea9b22082a496deadf90447a326954e < 716cba46f73a92645cf13eded8d257ed48afc2a4716cba46f73a92645cf13eded8d257ed48afc2a4
linuxlinux>= 54f83b8c8ea9b22082a496deadf90447a326954e < 973a57891608a98e894db2887f278777f564de18973a57891608a98e894db2887f278777f564de18
linuxlinux>= d1c188d330ca33cc35d1590441ba276f31144299 < ba15815dd24cc5ec0d23e2170dc58c7db1e03b4aba15815dd24cc5ec0d23e2170dc58c7db1e03b4a
linuxlinux_kernel< 3.16.803.16.80
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.