Bug 2322320 (CVE-2024-50075)
| Summary: | CVE-2024-50075 kernel: xhci: tegra: fix checked USB2 port number | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | dfreiber, drow, jburrell, rhel-process-autobot, vkumar, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A flaw was found in the Linux kernel's xHCI (eXtensible Host Controller Interface) Tegra driver. When USB virtualization is enabled and USB2 ports are shared across virtual functions, an incorrect port number check can lead to invalid memory access. A local attacker with high privileges could exploit this vulnerability to cause a system crash (Denial of Service) or potentially disclose sensitive information.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2322361 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2024-10-29 01:02:14 UTC
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024102935-CVE-2024-50075-81b7@gregkh/T This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:6966 https://access.redhat.com/errata/RHSA-2025:6966 |