CVE-2024-25741

Description

A flaw was found in the f_printer driver in the Linux kernel. Due to an incorrect use of the USB Gadget API, the printer_write function in the drivers/usb/gadget/function/f_printer.c file can trigger a WARN_ON_ONCE in the usb_ep_queue function in the drivers/usb/gadget/udc/core.c file, resulting in a denial of service.

Statement

The kernel as shipped by Red Hat Enterprise Linux 8 is not affected by this vulnerability because the f_printer and the USB Gadget driver/API is not enabled. In Red Hat Enterprise Linux 9, the f_printer driver is not enable as well, but the USB Gadget driver/API, where the WARN_ON_ONCE is triggered, is available in the aarch64 architecture.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score5.55.5N/A
Attack VectorLocalLocalN/A
Attack ComplexityLowLowN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Other

Technical Impact: Alter Execution Logic

Frequently Asked Questions

Want to get errata notifications? Sign up here.