Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: host: Fix dereference issue in DDMA completion flow. Fixed variable dereference issue in DDMA completion flow.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.15.154, < 5.15.157 |
| Debian | Debian Linux | 10.0 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/257d313e37d66c3bcc87197fb5b8549129c45dfePatch
- https://git.kernel.org/stable/c/26fde0ea40dda1b08fad3bc0a43f122f6dd8bddfPatch
- https://git.kernel.org/stable/c/55656b2afd5f1efcec4245f3e7e814c2a9ef53f6Patch
- https://git.kernel.org/stable/c/75bf5e78b2a27cb1bca6fa826e3ab685015165e1Patch
- https://git.kernel.org/stable/c/8a139fa44870e84ac228b7b76423a49610e5ba9aPatch
- https://git.kernel.org/stable/c/8aa5c28ac65cb5e7f1b9c0c3238c00b661dd2b8cPatch
- https://git.kernel.org/stable/c/9de10b59d16880a0a3ae2876c142fe54ce45d816Patch
- https://git.kernel.org/stable/c/eed04fa96c48790c1cce73c8a248e9d460b088f8Patch
- https://git.kernel.org/stable/c/257d313e37d66c3bcc87197fb5b8549129c45dfePatch
- https://git.kernel.org/stable/c/26fde0ea40dda1b08fad3bc0a43f122f6dd8bddfPatch
- https://git.kernel.org/stable/c/55656b2afd5f1efcec4245f3e7e814c2a9ef53f6Patch
- https://git.kernel.org/stable/c/75bf5e78b2a27cb1bca6fa826e3ab685015165e1Patch
- https://git.kernel.org/stable/c/8a139fa44870e84ac228b7b76423a49610e5ba9aPatch
- https://git.kernel.org/stable/c/8aa5c28ac65cb5e7f1b9c0c3238c00b661dd2b8cPatch
- https://git.kernel.org/stable/c/9de10b59d16880a0a3ae2876c142fe54ce45d816Patch
FAQ
What is CVE-2024-26997?
CVE-2024-26997 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: host: Fix dereference issue in DDMA completion flow. Fixed variable dereference issue in DDMA completion flow.
How severe is CVE-2024-26997?
CVE-2024-26997 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26997?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.