Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A memory corruption vulnerability has been identified in the Linux kernel's USB serial Omninet driver. This issue arises because the driver does not properly validate the size of bulk-out buffers before data transfer. If a malicious device reports a smaller maximum packet size than expected, it can lead to user-controlled slab corruption. The vulnerability affects several versions of the Linux kernel.
Exploitation of this vulnerability can cause memory corruption, allowing for potential arbitrary code execution or other unintended behavior.
The vulnerability can be reproduced by connecting a malicious USB device to a system running an affected version of the Linux kernel. The device must be configured to report a smaller maximum packet size than expected. When the device is connected, the Omninet driver will attempt to transfer data using the incorrect packet size, leading to memory corruption.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for upgrading the kernel can be found in the official Linux kernel documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.