CVE-2022-24958: High severity Google Android vulnerability
drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24958?
CVE-2022-24958 is classified as a medium severity vulnerability.
How do I fix CVE-2022-24958?
To fix CVE-2022-24958, ensure that your Linux kernel is updated to versions later than 5.16.8.
Which systems are affected by CVE-2022-24958?
CVE-2022-24958 affects versions of the Linux kernel up to and including 5.16.8, as well as certain versions of Google Android and Fedora.
What kind of vulnerability is CVE-2022-24958?
CVE-2022-24958 is a memory management vulnerability in the Linux kernel related to mishandling device buffer releases.
What are the potential impacts of CVE-2022-24958?
The potential impacts of CVE-2022-24958 include denial of service conditions or potential system instability.