Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A synchronization error vulnerability has been identified in the Linux kernel's USB dummy host controller driver. This issue arises from a race condition between USB reset handling and driver unbinding, which can lead to a crash by causing an addressing exception. The vulnerability is present in the USB gadget subsystem, specifically within the dummy_hcd driver.
Exploitation of this vulnerability causes a crash by provoking an addressing exception, disrupting normal operation of the USB gadget subsystem.
The vulnerability can be reproduced by emulating a USB reset while simultaneously unbinding the driver, creating a race condition that leads to a crash.
Users can apply the latest patches available in the Linux kernel stable tree to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.