In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.
2022-03-16T00:15:09.993
2024-11-21T06:55:26.460
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 4.9.304 | Yes |
Operating System | linux | linux_kernel | < 4.14.269 | Yes |
Operating System | linux | linux_kernel | < 4.19.232 | Yes |
Operating System | linux | linux_kernel | < 5.4.182 | Yes |
Operating System | linux | linux_kernel | < 5.10.103 | Yes |
Operating System | linux | linux_kernel | < 5.15.26 | Yes |
Operating System | linux | linux_kernel | < 5.16.12 | Yes |
Application | netapp | active_iq_unified_manager | - | Yes |
Operating System | netapp | h500s_firmware | - | Yes |
Hardware | netapp | h500s | - | No |
Operating System | netapp | h700s_firmware | - | Yes |
Hardware | netapp | h700s | - | No |
Operating System | netapp | h300e_firmware | - | Yes |
Hardware | netapp | h300e | - | No |
Operating System | netapp | h500e_firmware | - | Yes |
Hardware | netapp | h500e | - | No |
Operating System | netapp | h700e_firmware | - | Yes |
Hardware | netapp | h700e | - | No |
Operating System | netapp | h410s_firmware | - | Yes |
Hardware | netapp | h410s | - | No |
Operating System | netapp | h300s_firmware | - | Yes |
Hardware | netapp | h300s | - | No |
Operating System | debian | debian_linux | 9.0 | Yes |