CVE-2024-42236

Updated on 07 Aug 2024

Severity

5.5 Medium severity

Details

CVSS score
5.5
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()

Userspace provided string ’s’ could trivially have the length zero. Left unchecked this will firstly result in an OOB read in the form if (str[0 - 1] == '\n') followed closely by an OOB write in the form str[0 - 1] = ‘\0’`.

There is already a validating check to catch strings that are too long. Let’s supply an additional check for invalid strings that are too short.

Details

Affected packages:
kernel @ 2.6.32 (+15 more)

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: configfs: Prevent OOB read/write in usb_string_copy()

Userspace provided string ’s’ could trivially have the length zero. Left unchecked this will firstly result in an OOB read in the form if (str[0 - 1] == '\n') followed closely by an OOB write in the form str[0 - 1] = ‘\0’`.

There is already a validating check to catch strings that are too long. Let’s supply an additional check for invalid strings that are too short.

Fixes