CVE-2022-25258: Null Pointer Dereference
An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25258?
The severity of CVE-2022-25258 is classified as medium due to potential memory corruption risk.
How do I fix CVE-2022-25258?
To fix CVE-2022-25258, update your Linux kernel to version 5.16.10 or later.
What systems are affected by CVE-2022-25258?
CVE-2022-25258 affects Linux kernels prior to 5.16.10, and specific versions of Fedora and Debian.
What kind of vulnerability is CVE-2022-25258?
CVE-2022-25258 is a memory corruption vulnerability in the USB Gadget subsystem of the Linux kernel.
Can CVE-2022-25258 impact production environments?
Yes, CVE-2022-25258 can impact production environments by potentially allowing memory corruption and instability.