Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30572
HistoryMay 20, 2021 - 3:28 p.m.

Denial Of Service (DoS)

2021-05-2015:28:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24

0.001 Low

EPSS

Percentile

43.3%

usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. A use-after-free flaw was found in usb_sg_cancel in drivers/usb/core/message.c in the USB core subsystem. This flaw allows a local attacker with a special user or root privileges to crash the system due to a race problem in the scatter-gather cancellation and transfer completion in usb_sg_wait.

References