In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: gadget: fix NULL pointer dereference in ep_queue When the gadget endpoint is disabled or not yet configured, the ep->desc pointer can be NULL. This leads to a NULL pointer dereference when __cdns3_gadget_ep_queue() is called, causing a kernel crash. Add a check to return -ESHUTDOWN if ep->desc is NULL, which is the standard return code for unconfigured endpoints. This prevents potential crashes when ep_queue is called on endpoints that are not ready.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 10 Version 1809 for 32-bit Systems |
| Linux | Linux | 10 Version 1809 for x64-based Systems |
| Linux | Linux | < 10.0.17763.1999 |
| Linux | Linux | < 10.0.19043.1052 |