CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel affects the USB subsystem, specifically in the c67x00 driver, where a use-after-free condition can occur during the handling of isochronous URBs. This flaw can lead to potential memory corruption, allowing attackers to exploit freed memory, which may result in system instability or arbitrary code execution. Organizations using affected Linux systems, particularly those relying on USB devices managed by the c67x00 driver, should prioritize applying the patch to mitigate these risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: USB: c67x00: fix use-after-free in c67x00_add_iso_urb() When TD creation fails for the last packet of an isochronous URB, c67x00_add_iso_urb() gives the URB back before updating the endpoint scheduling state. c67x00_giveback_urb() frees the URB private data, and the completion callback may release the final URB reference. The following accesses to urbp->ep_data, urb->interval, and urbp->cnt can therefore use freed memory. Update next_frame and cnt before giving back the failed final packet, making the giveback the last operation that uses the URB and its private data.