CVE-2022-24958

Executive Summary

CVE-2022-24958 exposes a flaw in the Linux kernel (up to 5.16.8) where the USB gadget legacy inode.c mishandles dev->buf release, potentially leading to memory corruption and privilege escalation. The vulnerability could allow an attacker with local access to gain elevated privileges or crash the system.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-02-11T06:15:06.717 - Last Modified: 2026-09-11T16:17:32.383

Original Description: drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

"Being right is highly overrated. Even a stopped clock is right twice a day."

— Unknown
Source: NVD