linux is vulnerable to denial of service. The vulnerability exists in the drivers/usb/gadget/composite.c
due to the lack of validation in the interface OS descriptor requests, allowing an attacker to cause an application crash
git://git.launchpad.net/ubuntu-cve-tracker/tree/active/CVE-2022-25258
cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.10
github.com/szymonh/d-os-descriptor
github.com/torvalds/linux/commit/75e5b4849b81e19e9efe1654b30d7f3151c33c2c
lists.debian.org/debian-lts-announce/2022/03/msg00011.html
lists.debian.org/debian-lts-announce/2022/03/msg00012.html
lists.fedoraproject.org/archives/list/[email protected]/message/TCW2KZYJ2H6BKZE3CVLHRIXYDGNYYC5P/
security.netapp.com/advisory/ntap-20221028-0007/
www.debian.org/security/2022/dsa-5092
www.debian.org/security/2022/dsa-5096