CVE-2022-24958
Executive Summary
CVE-2022-24958 exposes a flaw in the Linux kernel (up to 5.16.8) where the USB gadget legacy inode.c mishandles dev->buf release, potentially leading to memory corruption and privilege escalation. The vulnerability could allow an attacker with local access to gain elevated privileges or crash the system.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-02-11T06:15:06.717 - Last Modified: 2026-09-11T16:17:32.383
Original Description: drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.
"Being right is highly overrated. Even a stopped clock is right twice a day."
— Unknown
Source: NVD