cbcvebase.
CVE-2024-56698
published 2024-12-28

CVE-2024-56698: In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix looping of queued SG entries The dwc3_request->num_queued_sgs is…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.5th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix looping of queued SG entries The dwc3_request->num_queued_sgs is decremented on completion. If a partially completed request is handled, then the dwc3_request->num_queued_sgs no longer reflects the total number of num_queued_sgs (it would be cleared). Correctly check the number of request SG entries remained to be prepare and queued. Failure to do this may cause null pointer dereference when accessing non-existent SG entry.

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= c96e6725db9d6a04ac1bee881e3034b636d9f71c < 8ceb21d76426bbe7072cc3e43281e70c0d664cc78ceb21d76426bbe7072cc3e43281e70c0d664cc7
linuxlinux>= c96e6725db9d6a04ac1bee881e3034b636d9f71c < 0247da93bf62d33304b7bf97850ebf2a86e06d280247da93bf62d33304b7bf97850ebf2a86e06d28
linuxlinux>= c96e6725db9d6a04ac1bee881e3034b636d9f71c < c9e72352a10ae89a430449f7bfeb043e75c255d9c9e72352a10ae89a430449f7bfeb043e75c255d9
linuxlinux>= c96e6725db9d6a04ac1bee881e3034b636d9f71c < 1534f6f69393aac773465d80d31801b5543526271534f6f69393aac773465d80d31801b554352627
linuxlinux>= c96e6725db9d6a04ac1bee881e3034b636d9f71c < b7c3d0b59213ebeedff63d128728ce0b3d7a51ecb7c3d0b59213ebeedff63d128728ce0b3d7a51ec
linuxlinux>= c96e6725db9d6a04ac1bee881e3034b636d9f71c < 70777a23a54e359cfdfafc625a57cd56434f385970777a23a54e359cfdfafc625a57cd56434f3859
linuxlinux>= c96e6725db9d6a04ac1bee881e3034b636d9f71c < b7fc65f5141c24785dc8c19249ca4efcf71b3524b7fc65f5141c24785dc8c19249ca4efcf71b3524
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 6.12.3-16.12.3-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.18 < 5.10.2315.10.231
linuxlinux_kernel>= 5.11 < 5.15.1745.15.174
linuxlinux_kernel>= 5.16 < 6.1.1206.1.120
linuxlinux_kernel>= 6.12 < 6.12.26.12.2
linuxlinux_kernel>= 6.2 < 6.6.646.6.64
linuxlinux_kernel>= 6.7 < 6.11.116.11.11
msrccbl2_kernel_5.15.173.1-2_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.