Description: | Summary: The remote host is missing an update for the 'linux-gkeop' package(s) announced via the USN-7156-1 advisory.
Vulnerability Insight: Chenyuan Yang discovered that the USB Gadget subsystem in the Linux kernel did not properly check for the device to be enabled before writing. A local attacker could possibly use this to cause a denial of service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture, - ARM64 architecture, - MIPS architecture, - PA-RISC architecture, - PowerPC architecture, - RISC-V architecture, - S390 architecture, - User-Mode Linux (UML), - x86 architecture, - Block layer subsystem, - Cryptographic API, - Android drivers, - Serial ATA and Parallel ATA drivers, - ATM drivers, - Drivers core, - Null block device driver, - Ublk userspace block driver, - Bluetooth drivers, - Cdrom driver, - Character device driver, - Clock framework and drivers, - Hardware crypto device drivers, - CXL (Compute Express Link) drivers, - Buffer Sharing and Synchronization framework, - DMA engine subsystem, - Cirrus firmware drivers, - Qualcomm firmware drivers, - GPIO subsystem, - GPU drivers, - HID subsystem, - Hardware monitoring drivers, - I2C subsystem, - I3C subsystem, - IIO subsystem, - InfiniBand drivers, - Input Device core drivers, - Input Device (Miscellaneous) drivers, - IOMMU subsystem, - IRQ chip drivers, - ISDN/mISDN subsystem, - LED subsystem, - Mailbox framework, - Multiple devices driver, - Media drivers, - Fastrpc Driver, - VMware VMCI Driver, - MMC subsystem, - Ethernet bonding driver, - Network drivers, - Mellanox network drivers, - Microsoft Azure Network Adapter (MANA) driver, - Near Field Communication (NFC) drivers, - NVME drivers, - NVMEM (Non Volatile Memory) drivers, - Device tree and open firmware driver, - Parport drivers, - PCI subsystem, - Pin controllers subsystem, - x86 platform drivers, - Power supply drivers, - Remote Processor subsystem, - S/390 drivers, - SCSI subsystem, - QCOM SoC drivers, - SPI subsystem, - Direct Digital Synthesis drivers, - Thermal drivers, - Thunderbolt and USB4 drivers, - TTY drivers, - UFS subsystem, - Userspace I/O drivers, - USB DSL drivers, - USB core drivers, - DesignWare USB3 driver, - USB Gadget drivers, - USB Host Controller drivers, - USB Serial drivers, - USB Type-C Connector System Software Interface driver, - USB over IP driver, - VFIO drivers, - Virtio Host (VHOST) subsystem, - Framebuffer layer, - Xen hypervisor drivers, - File systems infrastructure, - BTRFS file system, - Ext4 file system, - F2FS file system, - GFS2 file system, - JFFS2 file system, - JFS file system, - Network file systems library, - Network file system (NFS) client, - Network file system (NFS) server daemon, - NILFS2 file system, - File system notification infrastructure, - NTFS3 file system, - Proc file ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'linux-gkeop' package(s) on Ubuntu 24.04.
Solution: Please install the updated package(s).
CVSS Score: 9.0
CVSS Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C
|