CVE-2024-50075

MEDIUM

Linux Kernel 6.3-6.6.57, 6.7-6.11.4 - Memory Corruption via USB2 Port Validation

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: xhci: tegra: fix checked USB2 port number If USB virtualizatoin is enabled, USB2 ports are shared between all Virtual Functions. The USB2 port number owned by an USB2 root hub in a Virtual Function may be less than total USB2 phy number supported by the Tegra XUSB controller. Using total USB2 phy number as port number to check all PORTSC values would cause invalid memory access. [ 116.923438] Unable to handle kernel paging request at virtual address 006c622f7665642f ... [ 117.213640] Call trace: [ 117.216783] tegra_xusb_enter_elpg+0x23c/0x658 [ 117.222021] tegra_xusb_runtime_suspend+0x40/0x68 [ 117.227260] pm_generic_runtime_suspend+0x30/0x50 [ 117.232847] __rpm_callback+0x84/0x3c0 [ 117.237038] rpm_suspend+0x2dc/0x740 [ 117.241229] pm_runtime_work+0xa0/0xb8 [ 117.245769] process_scheduled_works+0x24c/0x478 [ 117.251007] worker_thread+0x23c/0x328 [ 117.255547] kthread+0x104/0x1b0 [ 117.259389] ret_from_fork+0x10/0x20 [ 117.263582] Code: 54000222 f9461ae8 f8747908 b4ffff48 (f9400100)

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 10.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (12)
linux/Kernel 6.3.0 - 6.6.58linux
linux/Kernel 6.7.0 - 6.11.5linux
Linux/Linux < 6.3
Linux/Linux 6.11.5 - 6.11.*
Linux/Linux 6.12
Linux/Linux 6.3
Linux/Linux 6.6.58 - 6.6.*
Linux/Linux a30951d31b250bf3479c00e93646b6cc6fb42a56 - 7d381137cb6ecf558ef6698c7730ddd482d4c8f2
Linux/Linux a30951d31b250bf3479c00e93646b6cc6fb42a56 - 9c696bf4ab54c7cec81221887564305f0ceeac0a
Linux/Linux a30951d31b250bf3479c00e93646b6cc6fb42a56 - c46555f14b71f95a447f5d49fc3f1f80a1472da2
... and 2 more
Published Oct 29, 2024
Tracked Since Feb 18, 2026