CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's ALSA subsystem, specifically in the handling of malformed USB devices that provide vendor-specific interfaces without endpoint descriptors. This flaw can lead to a NULL pointer dereference when the system attempts to access an invalid endpoint descriptor, potentially causing a denial of service. Linux system administrators and developers working with USB device drivers should prioritize this issue to ensure system stability and security.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: Fix NULL pointer dereference in interface lookup A malformed USB device can provide a vendor-specific interface without any endpoint descriptors. fcp_find_fc_interface() currently selects the first vendor-specific interface and reads endpoint 0 from it, without checking whether the interface actually has any endpoints. When bNumEndpoints is zero, no endpoint array is allocated for the parsed alternate setting, so get_endpoint(..., 0) yields an invalid endpoint descriptor pointer. Dereferencing it through usb_endpoint_num() then triggers a NULL pointer dereference. Skip vendor-specific interfaces that do not have any endpoints.