Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's USB-audio driver for Scarlett2 mixers can lead to a NULL pointer dereference. This issue arises when a malformed USB descriptor is received, as the driver expects an endpoint to be present in the parsed interface. The vulnerability has been reported by a fuzzer.
Exploitation of this vulnerability can cause a NULL pointer dereference, leading to a crash of the affected application or service.
The vulnerability can be reproduced by sending a malformed USB descriptor to a device using the Scarlett2 mixer. This can be done using a USB fuzzer that targets the audio interface.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.