PT-2024-3352 · Linux+6 · Linux Kernel+6

Uttkarsh Aggarwal

·

Published

2024-01-27

·

Updated

2026-03-14

·

CVE-2024-26715

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to a NULL pointer dereference in the dwc3 gadget suspend() function. This can occur when Plug-out and Plug-In actions are performed continuously, leading to a situation where the dwc->gadget driver variable is checked and found to be NULL, resulting in a NULL pointer dereference. The call stack involves gadget unbind driver, dwc3 suspend common, dwc3 gadget stop, dwc3 gadget suspend, and dwc3 disconnect gadget functions. This issue can potentially allow an attacker to cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-03624
CVE-2024-26715
DSA-5658-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2190-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6795-1
USN-6828-1
USN-6895-1
USN-6895-2
USN-6895-3
USN-6895-4
USN-6900-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu