vendor:
RHEL 7.1
by:
Sergej Schumilo, Hendrik Schwartke, Ralf Spenneberg
9
CVSS
CRITICAL
Wrong input validation
20
CWE
Product Name: RHEL 7.1
Affected Version From: RHEL 7.1
Affected Version To: RHEL 7.1 including all updates
Patch Exists: NO
Related CWE: not yet assigned
CPE: o:redhat:enterprise_linux:7.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2016
OS-S Security Advisory 2016-17 Linux snd-usb-audio Multiple Free
The Kernel 3.10.0-229.20.1.el7.x86_64 crashes on presentation of a buggy USB device requiring the snd-usb-audio driver. The bug was found using the USB-fuzzing framework vUSBf from Sergej Schumilo (github.com/schumilo) using the following device descriptor: [bLength: 0x12, bDescriptorType: 0x1, bcdUSB: 0x200, bDeviceClass: 0x3, bDeviceSubClass: 0x0, bDeviceProtocol: 0x0, bMaxPacketSize: 0x40, idVendor: 0x582, idProduct: 0x0, bcdDevice: 0x100, iManufacturer: 0x1, iProduct: 0x2, iSerialNumbers: 0x3, bNumConfigurations: 0x1]. This is the configuration descriptor containing the malicious value for bNumEndpoints causing the crash. A zero value for bNumEndpoints crashes the system (multiple free).
Mitigation:
No mitigation available yet.