CVE-2022-25258

NameCVE-2022-25258
DescriptionAn issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2940-1, DLA-2941-1, DSA-5092-1, DSA-5096-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1fixed
bullseye (security)5.10.244-1fixed
bookworm6.1.148-1fixed
bookworm (security)6.1.153-1fixed
trixie6.12.43-1fixed
trixie (security)6.12.48-1fixed
forky, sid6.16.12-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcestretch4.9.303-1DLA-2940-1
linuxsourcebuster4.19.232-1DSA-5096-1
linuxsourcebullseye5.10.92-2DSA-5092-1
linuxsource(unstable)5.16.10-1
linux-4.19sourcestretch4.19.232-1~deb9u1DLA-2941-1

Notes

https://github.com/szymonh/d-os-descriptor
https://git.kernel.org/linus/75e5b4849b81e19e9efe1654b30d7f3151c33c2c (5.17-rc4)

Search for package or bug name: Reporting problems