Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local users to cause a denial of service (out-of-bounds write access) or possibly have unspecified other impact via a crafted USB device.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Linux kernel USB core子系统缓冲区错误漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。USB core subsystem是其中的一个USB核心子系统。 Linux kernel 4.14.5及之前的版本中的USB core子系统的drivers/usb/core/config.c文件的‘usb_destroy_configuration’函数存在缓冲区错误漏洞,该漏洞源于程序在释放资源前,没有考虑配置和界面的最大数值。本地攻击者可利用该漏洞造成拒绝服务(越边界访问)。
CVSS Information
N/A
Vulnerability Type
N/A