Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A memory corruption vulnerability has been addressed in the Linux kernel's USB serial MXUport driver. The issue arose because the driver did not properly validate the maximum packet size of bulk-out endpoints, allowing user-controlled slab corruption. This could occur if a malicious device reported a smaller endpoint size, leading to memory corruption. The vulnerability affects several versions of the Linux kernel.
The vulnerability could be exploited to cause memory corruption, potentially leading to arbitrary code execution or other malicious actions.
The vulnerability can be reproduced by connecting a malicious USB device that reports a bulk-out endpoint maximum packet size of less than eight bytes. This will trigger the memory corruption issue in the MXUport driver.
Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for updating the kernel can be found in the official Linux kernel documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.