PT-2022-7633 · Linux+3 · Linux Kernel+3

Syzbot

·

Published

2022-03-15

·

Updated

2025-01-22

·

CVE-2022-48834

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a bug in the usbtmc driver, where the usbtmc ioctl request() function uses usb rcvctrlpipe() for all transfers, whether they are in or out. This can cause problems with pipe direction for control transfers. The syzbot fuzzer reported a minor bug in the usbtmc driver, which was identified by a warning message indicating a mismatch between the control direction and the pipe. The problem is easy to fix.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07586
CVE-2022-48834
OPENSUSE-SU-2024_2947-1
OPENSUSE-SU-2024_3249-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:3225-1
SUSE-SU-2024:3249-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse