
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-42244 affects the Linux kernel's USB serial driver for MOS7840 devices. The vulnerability was discovered in the driver's resume functionality, where a crash could occur due to improper handling of URB (USB Request Block) context pointers. The issue affects Linux kernel versions from 3.3 up to (excluding) versions 5.10.222, 5.15.163, 6.1.100, 6.6.41, and 6.9.10 (NVD).
The vulnerability stems from a change introduced by commit c49cfa917025 ("USB: serial: use generic method if no alternative is provided in usb serial layer"), where the USB serial core calls the generic resume implementation when the driver hasn't provided one. This implementation can trigger a crash on resume with mos7840 devices since support for multiple read URBs was added in 2011. Specifically, both port read URBs are submitted on resume for open ports, but the context pointer of the second URB is incorrectly set to the core rather than the mos7840 port structure. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).
When exploited, this vulnerability can cause a system crash during the resume operation of affected USB serial devices using the MOS7840 driver. The impact is limited to availability (denial of service) with no direct impact on confidentiality or integrity (NVD).
The vulnerability requires local access and can be triggered during the resume operation of affected USB serial devices. It has been confirmed to affect devices such as the Delock 87414 USB 2.0 to 4x serial adapter (Kernel Patch).
The vulnerability has been fixed by implementing dedicated suspend and resume functions for the mos7840 driver. The fix includes proper handling of URB context pointers and management of the read_urb_busy flag. Users should update to kernel versions 5.10.222, 5.15.163, 6.1.100, 6.6.41, 6.9.10 or later which contain the fix (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."