Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A memory corruption vulnerability has been identified in the Linux kernel's USB serial 'safe_serial' driver. This issue arises when a malicious device reports a bulk-out buffer size smaller than eight bytes, leading to user-controlled slab corruption in 'safe' mode. The vulnerability is present in several versions of the Linux kernel.
Exploitation of this vulnerability can lead to memory corruption, allowing for potential manipulation of the kernel's memory management, which could be exploited to execute arbitrary code or cause a denial-of-service condition.
The vulnerability can be reproduced by connecting a malicious USB device that reports a bulk-out buffer size of less than eight bytes to a system running an affected version of the Linux kernel. This will trigger the 'safe' mode in the 'safe_serial' driver, causing the memory corruption issue.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for upgrading the kernel can be found in the official Linux kernel documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.