CVE

CVE-2022-25258

CVE-2022-25258

An issue was discovered in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.

Source: CVE-2022-25258

Exit mobile version