Updated: 2026-03-05 01:07:51.304188
Description:
drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | MEDIUM | 4.6 |
| CVSS Version 3.x | MEDIUM | 6.8 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| CentOS 6 ELS | kernel | 2.6.32 | 6.8 | MEDIUM | Not Vulnerable | 2022-01-04 14:20:18 | Not affected: this flaw is limited to the MAX3421 USB-over-SPI host controller driver (CONFIG_USB_MA... | |
| CentOS 7 ELS | kernel | 3.10.0 | 6.8 | MEDIUM | Ignored | 2023-09-19 09:30:08 | Ignored due to low severity | |
| CentOS 8.4 ELS | kernel | 4.18.0 | 6.8 | MEDIUM | Ignored | 2022-02-10 08:36:35 | Ignored due to low severity | |
| CentOS 8.5 ELS | kernel | 4.18.0 | 6.8 | MEDIUM | Ignored | 2022-02-21 05:39:39 | Ignored due to low severity | |
| CloudLinux 6 ELS | kernel | 2.6.32 | 6.8 | MEDIUM | Ignored | 2022-01-27 11:20:19 | Ignored due to low severity | |
| Oracle Linux 6 ELS | kernel | 2.6.32 | 6.8 | MEDIUM | Ignored | 2022-01-27 11:20:19 | Ignored due to low severity | |
| Ubuntu 16.04 ELS | linux-hwe | 4.15.0 | 6.8 | MEDIUM | Ignored | 2022-09-28 08:02:37 | Ignored due to low severity | |
| Ubuntu 16.04 ELS | linux | 4.4.0 | 6.8 | MEDIUM | Released | CLSA-2022:1643637294 | 2022-01-31 11:45:18 | Ignored due to low severity |
| Ubuntu 18.04 ELS | linux | 4.15.0 | 6.8 | MEDIUM | Ignored | 2023-03-02 04:04:09 | Ignored due to low severity |