SB2024032826 - Local denial of service in Linux kernel sr9800 driver
Published: March 28, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Unchecked Return Value (CVE-ID: CVE-2024-26651)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a missing check of the return value from the usbnet_get_endpoints() function in drivers/net/usb/sr9800.c. A local user can crash the kernel.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/424eba06ed405d557077339edb19ce0ebe39e7c7
- https://git.kernel.org/stable/c/8a8b6a24684bc278036c3f159f7b3a31ad89546a
- https://git.kernel.org/stable/c/6b4a39acafaf0186ed8e97c16e0aa6fca0e52009
- https://git.kernel.org/stable/c/276873ae26c8d75b00747c1dadb9561d6ef20581
- https://git.kernel.org/stable/c/9c402819620a842cbfe39359a3ddfaac9adc8384
- https://git.kernel.org/stable/c/e39a3a14eafcf17f03c037290b78c8f483529028
- https://git.kernel.org/stable/c/efba65777f98457773c5b65e3135c6132d3b015f
- https://git.kernel.org/stable/c/f546cc19f9b82975238d0ba413adc27714750774
- https://git.kernel.org/stable/c/07161b2416f740a2cb87faa5566873f401440a61
- https://bugzilla.redhat.com/show_bug.cgi?id=2271873