PT-2024-3352 · Linux+6 · Linux Kernel+6
Uttkarsh Aggarwal
·
Published
2024-01-27
·
Updated
2026-03-14
·
CVE-2024-26715
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to a NULL pointer dereference in the
dwc3 gadget suspend() function. This can occur when Plug-out and Plug-In actions are performed continuously, leading to a situation where the dwc->gadget driver variable is checked and found to be NULL, resulting in a NULL pointer dereference. The call stack involves gadget unbind driver, dwc3 suspend common, dwc3 gadget stop, dwc3 gadget suspend, and dwc3 disconnect gadget functions. This issue can potentially allow an attacker to cause a denial of service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu