REDHAT-BUG-2348566: Low severity Linux Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved:
HID: hid-thrustmaster: Fix warning in thrustmasterprobe by adding endpoint check
syzbot has found a type mismatch between a USB pipe and the transfer endpoint, which is triggered by the hid-thrustmaster driver[1]. There is a number of similar, already fixed issues [2]. In this case as in others, implementing check for endpoint type fixes the issue.
[1] https://syzkaller.appspot.com/bug?extid=040e8b3db6a96908d470 [2] https://syzkaller.appspot.com/bug?extid=348331f63b034f89b622
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2348566?
The severity of REDHAT-BUG-2348566 is categorized as a moderate risk due to the type mismatch found in the hid-thrustmaster driver.
How do I fix REDHAT-BUG-2348566?
To fix REDHAT-BUG-2348566, ensure that you update your Linux kernel to the latest version that has addressed this vulnerability.
Which systems are affected by REDHAT-BUG-2348566?
All systems using the impacted versions of the Linux kernel that utilize the hid-thrustmaster driver are affected by REDHAT-BUG-2348566.
When was REDHAT-BUG-2348566 reported?
REDHAT-BUG-2348566 was reported after syzbot identified the vulnerability during testing of the Linux kernel.
What components are involved in REDHAT-BUG-2348566?
The components involved in REDHAT-BUG-2348566 include the hid-thrustmaster driver and the USB pipe managing data transfers.