CVE-2024-41035 - CVE House
Back to Database
Status published Unknown CVE-2024-41035

USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix duplicate endpoint bug by clearing reserved bits in the descriptor Syzbot has identified a bug in usbcore (see the Closes: tag below) caused by our assumption that the reserved bits in an endpoint descriptor's bEndpointAddress field will always be 0. As a result of the bug, the endpoint_is_duplicate() routine in config.c (and possibly other routines as well) may believe that two descriptors are for distinct endpoints, even though they have the same direction and endpoint number. This can lead to confusion, including the bug identified by syzbot (two descriptors with matching endpoint numbers and directions, where one was interrupt and the other was bulk). To fix the bug, we will clear the reserved bits in bEndpointAddress when we parse the descriptor. (Note that both the USB-2.0 and USB-3.1 specs say these bits are "Reserved, reset to zero".) This requires us to make a copy of the descriptor earlier in usb_parse_endpoint() and use the copy instead of the original when checking for duplicates.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-41035

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
0a8fd1346254974c3a852338508e4a4cddbb35f1, c3726b442527ab31c7110d0445411f5b5343db01, 15668b4354b38b41b316571deed2763d631b2977, 8597a9245181656ae2ef341906e5f40af323fbca, 264024a2676ba7d91fe7b1713b2c32d1b0b508cb, b0de742a1be16b76b534d088682f18cf57f012d2, 7cc00abef071a8a7d0f4457b7afa2f57f683d83f, 05b0f2fc3c2f9efda47439557e0d51faca7e43ed, 3.2.87, 3.10.106, 3.12.70, 3.16.42, 4.1.39, 4.4.42, 4.9.3, 4.10, 0, 4.19.318, 5.4.280, 5.10.222, 5.15.163, 6.1.100, 6.6.41, 6.9.10, 6.10

Timeline

Official Publish: July 29th, 2024
Last Modified: May 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.