CVE-2024-47671
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: prevent kernel-usb-infoleak The syzbot reported a kernel-usb-infoleak in usbtmc_write, we need to clear the structure before filling fields.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.01%• Percentile: 2%
Affected Systems
- linux•linux
≥ 4ddc645f40e90fa3bc7af3a3f3bd7d29e671a775, < fa652318887da530f2f9dbd9b0ea4a087d05ee12 | ≥ 4ddc645f40e90fa3bc7af3a3f3bd7d29e671a775, < 16e0ab9ed3ae7d19ca8ee718ba4e09d5c0f909ca | ≥ 4ddc645f40e90fa3bc7af3a3f3bd7d29e671a775, < 0c927dfc0b9bd177f7ab6ee59ef0c4ea06c110a7 | ≥ 4ddc645f40e90fa3bc7af3a3f3bd7d29e671a775, < ba6269e187aa1b1f20faf3c458831a0d6350304b | ≥ 4ddc645f40e90fa3bc7af3a3f3bd7d29e671a775, < 51297ef7ad7824ad577337f273cd092e81a9fa08 | ≥ 4ddc645f40e90fa3bc7af3a3f3bd7d29e671a775, < e872738e670ddd63e19f22d0d784f0bdf26ecba5 | ≥ 4ddc645f40e90fa3bc7af3a3f3bd7d29e671a775, < 6c7fc36da021b13c34c572a26ba336cd102418f8 | ≥ 4ddc645f40e90fa3bc7af3a3f3bd7d29e671a775, < 625fa77151f00c1bd00d34d60d6f2e710b3f9aad | 4.20
- linux•linux_kernel
≥ 4.20, < 6.1.112 | ≥ 6.2, < 6.6.53 | ≥ 6.7, < 6.10.12 | 6.11:rc1 | 6.11:rc2 | 6.11:rc3 | 6.11:rc4 | 6.11:rc5 | 6.11:rc6 | 6.11:rc7 | 6.11:rc8 | 6.11.1
References (10)
- https://git.kernel.org/stable/c/fa652318887da530f2f9dbd9b0ea4a087d05ee12
- https://git.kernel.org/stable/c/16e0ab9ed3ae7d19ca8ee718ba4e09d5c0f909ca
- https://git.kernel.org/stable/c/0c927dfc0b9bd177f7ab6ee59ef0c4ea06c110a7
- https://git.kernel.org/stable/c/ba6269e187aa1b1f20faf3c458831a0d6350304b
- https://git.kernel.org/stable/c/51297ef7ad7824ad577337f273cd092e81a9fa08
- https://git.kernel.org/stable/c/e872738e670ddd63e19f22d0d784f0bdf26ecba5
- https://git.kernel.org/stable/c/6c7fc36da021b13c34c572a26ba336cd102418f8
- https://git.kernel.org/stable/c/625fa77151f00c1bd00d34d60d6f2e710b3f9aad
- https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html