CVE-2024-50075

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/10/2024
Last modified:
01/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> xhci: tegra: fix checked USB2 port number<br /> <br /> If USB virtualizatoin is enabled, USB2 ports are shared between all<br /> Virtual Functions. The USB2 port number owned by an USB2 root hub in<br /> a Virtual Function may be less than total USB2 phy number supported<br /> by the Tegra XUSB controller.<br /> <br /> Using total USB2 phy number as port number to check all PORTSC values<br /> would cause invalid memory access.<br /> <br /> [ 116.923438] Unable to handle kernel paging request at virtual address 006c622f7665642f<br /> ...<br /> [ 117.213640] Call trace:<br /> [ 117.216783] tegra_xusb_enter_elpg+0x23c/0x658<br /> [ 117.222021] tegra_xusb_runtime_suspend+0x40/0x68<br /> [ 117.227260] pm_generic_runtime_suspend+0x30/0x50<br /> [ 117.232847] __rpm_callback+0x84/0x3c0<br /> [ 117.237038] rpm_suspend+0x2dc/0x740<br /> [ 117.241229] pm_runtime_work+0xa0/0xb8<br /> [ 117.245769] process_scheduled_works+0x24c/0x478<br /> [ 117.251007] worker_thread+0x23c/0x328<br /> [ 117.255547] kthread+0x104/0x1b0<br /> [ 117.259389] ret_from_fork+0x10/0x20<br /> [ 117.263582] Code: 54000222 f9461ae8 f8747908 b4ffff48 (f9400100)

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.3 (including) 6.6.58 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.11.5 (excluding)
cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc3:*:*:*:*:*:*