Wind River Support Network

HomeDefectsLIN1021-12903
Fixed

LIN1021-12903 : Security Advisory - linux - CVE-2024-56698

Created: Dec 29, 2024    Updated: May 27, 2025
Resolved Date: May 21, 2025
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

usb: dwc3: gadget: Fix looping of queued SG entries

The dwc3_request->num_queued_sgs is decremented on completion. If a
partially completed request is handled, then the
dwc3_request->num_queued_sgs no longer reflects the total number of
num_queued_sgs (it would be cleared).

Correctly check the number of request SG entries remained to be prepare
and queued. Failure to do this may cause null pointer dereference when
accessing non-existent SG entry.

CREATE(Triage):(User=admin) CVE-2024-56698 (https://nvd.nist.gov/vuln/detail/CVE-2024-56698)

CVEs


Live chat
Online