| { |
| "containers": { |
| "cna": { |
| "providerMetadata": { |
| "orgId": "f4215fc3-5b6b-47ff-a258-f7189bd81038" |
| }, |
| "descriptions": [ |
| { |
| "lang": "en", |
| "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc2: host: Fix dereference issue in DDMA completion flow.\n\nFixed variable dereference issue in DDMA completion flow." |
| } |
| ], |
| "affected": [ |
| { |
| "product": "Linux", |
| "vendor": "Linux", |
| "defaultStatus": "unaffected", |
| "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", |
| "programFiles": [ |
| "drivers/usb/dwc2/hcd_ddma.c" |
| ], |
| "versions": [ |
| { |
| "version": "dca1dc1e99e09e7b8eaccb55d6aecb87d9cb8ecd", |
| "lessThan": "257d313e37d66c3bcc87197fb5b8549129c45dfe", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "693bbbccd9c774adacaf03ae9fcbb33b66b1ffc4", |
| "lessThan": "75bf5e78b2a27cb1bca6fa826e3ab685015165e1", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "db4fa0c8e811676a7bfe8363a01e70ee601e75f7", |
| "lessThan": "26fde0ea40dda1b08fad3bc0a43f122f6dd8bddf", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "32d3f2f108ebcaf9bd9fc06095c776cb73add034", |
| "lessThan": "8aa5c28ac65cb5e7f1b9c0c3238c00b661dd2b8c", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "bc48eb1b53ce977d17d51caa574bd81064a117a2", |
| "lessThan": "9de10b59d16880a0a3ae2876c142fe54ce45d816", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "8d310e5d702c903a7ac95fb5dd248f046b39db00", |
| "lessThan": "8a139fa44870e84ac228b7b76423a49610e5ba9a", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "8b7c57ab6f6bc6bfee87e929cab6e6dac351606b", |
| "lessThan": "55656b2afd5f1efcec4245f3e7e814c2a9ef53f6", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "b258e42688501cadb1a6dd658d6f015df9f32d8f", |
| "lessThan": "eed04fa96c48790c1cce73c8a248e9d460b088f8", |
| "status": "affected", |
| "versionType": "git" |
| }, |
| { |
| "version": "c4046e703e0083c8d2031cce02f2479e9ba2c166", |
| "status": "affected", |
| "versionType": "git" |
| } |
| ] |
| }, |
| { |
| "product": "Linux", |
| "vendor": "Linux", |
| "defaultStatus": "unaffected", |
| "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", |
| "programFiles": [ |
| "drivers/usb/dwc2/hcd_ddma.c" |
| ], |
| "versions": [ |
| { |
| "version": "4.19.312", |
| "lessThan": "4.19.313", |
| "status": "affected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.4.274", |
| "lessThan": "5.4.275", |
| "status": "affected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.10.215", |
| "lessThan": "5.10.216", |
| "status": "affected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "5.15.154", |
| "lessThan": "5.15.157", |
| "status": "affected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.1.84", |
| "lessThan": "6.1.88", |
| "status": "affected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.6.24", |
| "lessThan": "6.6.29", |
| "status": "affected", |
| "versionType": "semver" |
| }, |
| { |
| "version": "6.8.3", |
| "lessThan": "6.8.8", |
| "status": "affected", |
| "versionType": "semver" |
| } |
| ] |
| } |
| ], |
| "cpeApplicability": [ |
| { |
| "nodes": [ |
| { |
| "operator": "OR", |
| "negate": false, |
| "cpeMatch": [ |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "4.19.312", |
| "versionEndExcluding": "4.19.313" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "5.4.274", |
| "versionEndExcluding": "5.4.275" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "5.10.215", |
| "versionEndExcluding": "5.10.216" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "5.15.154", |
| "versionEndExcluding": "5.15.157" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.1.84", |
| "versionEndExcluding": "6.1.88" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.6.24", |
| "versionEndExcluding": "6.6.29" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.8.3", |
| "versionEndExcluding": "6.8.8" |
| }, |
| { |
| "vulnerable": true, |
| "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", |
| "versionStartIncluding": "6.7.12" |
| } |
| ] |
| } |
| ] |
| } |
| ], |
| "references": [ |
| { |
| "url": "https://git.kernel.org/stable/c/257d313e37d66c3bcc87197fb5b8549129c45dfe" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/75bf5e78b2a27cb1bca6fa826e3ab685015165e1" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/26fde0ea40dda1b08fad3bc0a43f122f6dd8bddf" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/8aa5c28ac65cb5e7f1b9c0c3238c00b661dd2b8c" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/9de10b59d16880a0a3ae2876c142fe54ce45d816" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/8a139fa44870e84ac228b7b76423a49610e5ba9a" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/55656b2afd5f1efcec4245f3e7e814c2a9ef53f6" |
| }, |
| { |
| "url": "https://git.kernel.org/stable/c/eed04fa96c48790c1cce73c8a248e9d460b088f8" |
| } |
| ], |
| "title": "usb: dwc2: host: Fix dereference issue in DDMA completion flow.", |
| "x_generator": { |
| "engine": "bippy-1.2.0" |
| } |
| } |
| }, |
| "cveMetadata": { |
| "assignerOrgId": "f4215fc3-5b6b-47ff-a258-f7189bd81038", |
| "cveID": "CVE-2024-26997", |
| "requesterUserId": "gregkh@kernel.org", |
| "serial": "1", |
| "state": "PUBLISHED" |
| }, |
| "dataType": "CVE_RECORD", |
| "dataVersion": "5.0" |
| } |