In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. This strictly speaking closes ZDI-CAN-22273, though there may be similar races in the driver.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 5.1.1 |
| Linux | Linux | 2008 for x64-based Systems Service Pack 2 |
| Linux | Linux | <= 5.10.* |
| Linux | Linux | < KRNL32UC - 7.22 |