cbcvebase.
CVE-2024-56670
published 2024-12-27

CVE-2024-56670: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.1th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer Considering that in some extreme cases, when u_serial driver is accessed by multiple threads, Thread A is executing the open operation and calling the gs_open, Thread B is executing the disconnect operation and calling the gserial_disconnect function,The port->port_usb pointer will be set to NULL. E.g. Thread A Thread B gs_open() gadget_unbind_driver() gs_start_io() composite_disconnect() gs_start_rx() gserial_disconnect() ... ... spin_unlock(&port->port_lock) status = usb_ep_queue() spin_lock(&port->port_lock) spin_lock(&port->port_lock) port->port_usb = NULL gs_free_requests(port->port_usb->in) spin_unlock(&port->port_lock) Crash This causes thread A to access a null pointer (port->port_usb is null) when calling the gs_free_requests function, causing a crash. If port_usb is NULL, the release request will be skipped as it will be done by gserial_disconnect. So add a null pointer check to gs_start_io before attempting to access the value of the pointer port->port_usb. Call trace: gs_start_io+0x164/0x25c gs_open+0x108/0x13c tty_open+0x314/0x638 chrdev_open+0x1b8/0x258 do_dentry_open+0x2c4/0x700 vfs_open+0x2c/0x3c path_openat+0xa64/0xc60 do_filp_open+0xb8/0x164 do_sys_openat2+0x84/0xf0 __arm64_sys_openat+0x70/0x9c invoke_syscall+0x58/0x114 el0_svc_common+0x80/0xe0 do_el0_svc+0x1c/0x28 el0_svc+0x38/0x68

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= c1dca562be8ada614ef193aa246c6f8705bcd6b9 < 4efdfdc32d8d6307f968cd99f1db64468471bab14efdfdc32d8d6307f968cd99f1db64468471bab1
linuxlinux>= c1dca562be8ada614ef193aa246c6f8705bcd6b9 < 28b3c03a6790de1f6f2683919ad657840f0f0f5828b3c03a6790de1f6f2683919ad657840f0f0f58
linuxlinux>= c1dca562be8ada614ef193aa246c6f8705bcd6b9 < 1247e1df086aa6c17ab53cd1bedce70dd71327651247e1df086aa6c17ab53cd1bedce70dd7132765
linuxlinux>= c1dca562be8ada614ef193aa246c6f8705bcd6b9 < c83213b6649d22656b3a4e92544ceeea8a2c6c07c83213b6649d22656b3a4e92544ceeea8a2c6c07
linuxlinux>= c1dca562be8ada614ef193aa246c6f8705bcd6b9 < 8ca07a3d18f39b1669927ef536e485787e856df68ca07a3d18f39b1669927ef536e485787e856df6
linuxlinux>= c1dca562be8ada614ef193aa246c6f8705bcd6b9 < dd6b0ca6025f64ccb465a6a3460c5b0307ed9c44dd6b0ca6025f64ccb465a6a3460c5b0307ed9c44
linuxlinux>= c1dca562be8ada614ef193aa246c6f8705bcd6b9 < 4cfbca86f6a8b801f3254e0e3c8f2b1d2d64be2b4cfbca86f6a8b801f3254e0e3c8f2b1d2d64be2b
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 2.6.27 < 5.4.2885.4.288
linuxlinux_kernel>= 5.11 < 5.15.1755.15.175
linuxlinux_kernel>= 5.16 < 6.1.1216.1.121
linuxlinux_kernel>= 5.5 < 5.10.2325.10.232
linuxlinux_kernel>= 6.2 < 6.6.676.6.67
linuxlinux_kernel>= 6.7 < 6.12.66.12.6
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.