CVE-2024-50075
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/10/2024
Last modified:
01/10/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
xhci: tegra: fix checked USB2 port number<br />
<br />
If USB virtualizatoin is enabled, USB2 ports are shared between all<br />
Virtual Functions. The USB2 port number owned by an USB2 root hub in<br />
a Virtual Function may be less than total USB2 phy number supported<br />
by the Tegra XUSB controller.<br />
<br />
Using total USB2 phy number as port number to check all PORTSC values<br />
would cause invalid memory access.<br />
<br />
[ 116.923438] Unable to handle kernel paging request at virtual address 006c622f7665642f<br />
...<br />
[ 117.213640] Call trace:<br />
[ 117.216783] tegra_xusb_enter_elpg+0x23c/0x658<br />
[ 117.222021] tegra_xusb_runtime_suspend+0x40/0x68<br />
[ 117.227260] pm_generic_runtime_suspend+0x30/0x50<br />
[ 117.232847] __rpm_callback+0x84/0x3c0<br />
[ 117.237038] rpm_suspend+0x2dc/0x740<br />
[ 117.241229] pm_runtime_work+0xa0/0xb8<br />
[ 117.245769] process_scheduled_works+0x24c/0x478<br />
[ 117.251007] worker_thread+0x23c/0x328<br />
[ 117.255547] kthread+0x104/0x1b0<br />
[ 117.259389] ret_from_fork+0x10/0x20<br />
[ 117.263582] Code: 54000222 f9461ae8 f8747908 b4ffff48 (f9400100)
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.3 (including) | 6.6.58 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.11.5 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:6.12:rc3:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



