ZeroHour

CVE-2022-25258

CVSS 3.1
4.6 medium
EPSS
<1%p58
Published
()
Modified
Description

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

Vendors
linuxfedoraprojectdebiannetapp
Products
linux kernel, fedora, debian linux, active iq unified manager, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware
Weakness
CWE-476
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.