Junglewise Threat Intelligence

CVE-2024-44960: Linux Kernel NULL pointer dereference in USB gadget core

CVE-2024-44960 · Severity: medium · CVSS 5.5 · Published 2024-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB gadget subsystem could allow a local user to cause a system crash (kernel panic). The issue occurs when the system processes malformed USB descriptors or improperly configured endpoints, leading to a 'null pointer' error. While primarily a risk during the development of new USB gadget drivers, it could be used to disrupt system availability.

Technical details

A NULL pointer dereference exists in the Linux kernel's USB gadget framework within 'drivers/usb/gadget/udc/core.c'. The function 'usb_ep_enable' attempted to access 'ep->desc' to check the 'maxpacket' size without first verifying that the descriptor pointer was non-null. This condition can be triggered by malformed gadget descriptors or endpoints that are not properly configured for the current connection speed. An attacker with local access could potentially trigger this crash to cause a Denial of Service (DoS). The issue has been resolved by adding a check for '!ep->desc' before accessing the descriptor.

Affected products

  • Linux Linux Kernel up to 6.10.5

Timeline

  • 2024-07-24: disclosed: Patch submitted by developer
  • 2024-09-04: advisory: CVE published by NVD

References

Related threats