CVE-2025-38474
Published: July 29, 2025Last modified: July 29, 2025
Description
In the Linux kernel, the following vulnerability has been resolved: usb: net: sierra: check for no status endpoint The driver checks for having three endpoints and having bulk in and out endpoints, but not that the third endpoint is interrupt input. Rectify the omission.
Status
Product | Release | Package | Status |
---|---|---|---|
Alpaquita Linux | 23 LTS | linux-lts | Fixed (6.1.147-r0) |
Stream | linux-lts | Fixed (6.6.100-r0) |
References
- https://git.kernel.org/stable/c/4c4ca3c46167518f8534ed70f6e3b4bf86c4d158
- https://git.kernel.org/stable/c/5849980faea1c792d1d5e54fdbf1e69ac0a9bfb9
- https://git.kernel.org/stable/c/5dd6a441748dad2f02e27b256984ca0b2d4546b6
- https://git.kernel.org/stable/c/65c666aff44eb7f9079c55331abd9687fb77ba2d
- https://git.kernel.org/stable/c/bfe8ef373986e8f185d3d6613eb1801a8749837a