A vulnerability in the Linux kernel USB Gadget subsystem that could potentially allow code execution.

A vulnerability (CVE-2021-39685) has been identified in USB Gadget, a subsystem of the Linux kernel that provides a software interface for creating client USB devices and software simulation of USB devices. This vulnerability may lead to information leakage from the kernel, crashes, or execution of arbitrary code at the kernel level. The attack can be carried out by an unprivileged local user through manipulation of various device classes implemented via the USB Gadget API, such as rndis, hid, uac1, uac1_legacy, and uac2.

The issue has been resolved in the recently released Linux kernel updates 5.15.8, 5.10.85, 5.4.165, 4.19.221, 4.14.258, 4.9.293, and 4.4.295. The problem still remains unaddressed in distributions (Debian, Ubuntu, RHEL, SUSE, Fedora, Arch). A prototype exploit has been prepared to demonstrate the vulnerability.

The problem is caused by a buffer overflow in the data transfer request handlers in gadget drivers rndis, hid, uac1, uac1_legacy, and uac2. As a result of exploiting this vulnerability, an unprivileged attacker can gain access to kernel memory by sending a special control request with the wLength field value exceeding the size of the static buffer that is always allocated 4096 bytes (USB_COMP_EP0_BUFSIZ). During the attack, it is possible to read or write up to 65 KB of data from an unprivileged user-space process into kernel memory.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster