Resource Management Errors Affecting torvalds/linux package, versions [,2.6.22.6)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-TORVALDSLINUX-3005182
  • published26 Jan 2022
  • disclosed26 Sept 2007
  • creditUnknown

Introduced: 26 Sep 2007

CVE-2007-5093  (opens in a new tab)
CWE-399  (opens in a new tab)

How to fix?

Upgrade torvalds/linux to version 2.6.22.6 or higher.

Overview

Affected versions of this package are vulnerable to Resource Management Errors. The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing the device after the disconnect is invoked. NOTE: this rarely crosses privilege boundaries, unless the attacker can convince the victim to unplug the affected device.

CVSS Base Scores

version 3.1