A vulnerability in the Linux kernel USB Gadget subsystem that could potentially allow code execution.
A vulnerability (CVE-2021-39685) has been discovered in USB Gadget, a subsystem of the Linux kernel that provides a programming interface for creating client USB devices and software simulation of USB devices. This vulnerability could lead to information leakage from the kernel, crashes, or arbitrary code execution at the kernel level. The attack can be executed by an unprivileged local user through manipulations with various device classes implemented over the USB Gadget API, such as […]
