<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 19:38:54 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-57913 — usb: gadget: f_fs: Remove WARN_ON in functionfs_bind</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-57913</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: f_fs: Remove WARN_ON in functionfs_bind&lt;/p&gt;
&lt;p&gt;This commit addresses an issue related to below kernel panic where
panic_on_warn is enabled. It is caused by the unnecessary use of WARN_ON
in functionsfs_bind, which easily leads to the following scenarios.&lt;/p&gt;
&lt;p&gt;1.adb_write in adbd               2. UDC write via configfs
  =================	             =====================&lt;/p&gt;
&lt;p&gt;-&amp;gt;usb_ffs_open_thread()           -&amp;gt;UDC write
 -&amp;gt;open_functionfs()               -&amp;gt;configfs_write_iter()
  -&amp;gt;adb_open()                      -&amp;gt;gadget_dev_desc_UDC_store()
   -&amp;gt;adb_write()                     -&amp;gt;usb_gadget_register_driver_owner
                                      -&amp;gt;driver_register()
-&amp;gt;StartMonitor()                       -&amp;gt;bus_add_driver()
 -&amp;gt;adb_read()                           -&amp;gt;gadget_bind_driver()
&amp;lt;times-out without BIND event&amp;gt;           -&amp;gt;configfs_composite_bind()
                                          -&amp;gt;usb_add_function()
-&amp;gt;open_functionfs()                        -&amp;gt;ffs_func_bind()
 -&amp;gt;adb_open()                               -&amp;gt;functionfs_bind()
                                       &amp;lt;ffs-&amp;gt;state !=FFS_ACTIVE&amp;gt;&lt;/p&gt;
&lt;p&gt;The adb_open, adb_read, and adb_write operations are invoked from the
daemon, but trying to bind the function is a process that is invoked by
UDC write through configfs, which opens up the possibility of a race
condition between the two paths. In this race scenario, the kernel panic
occurs due to the WARN…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: f_fs: Remove WARN_ON in functionfs_bind&lt;/p&gt;
&lt;p&gt;This commit addresses an issue related to below kernel panic where
panic_on_warn is enabled. It is caused by the unnecessary use of WARN_ON
in functionsfs_bind, which easily leads to the following scenarios.&lt;/p&gt;
&lt;p&gt;1.adb_write in adbd               2. UDC write via configfs
  =================	             =====================&lt;/p&gt;
&lt;p&gt;-&amp;gt;usb_ffs_open_thread()           -&amp;gt;UDC write
 -&amp;gt;open_functionfs()               -&amp;gt;configfs_write_iter()
  -&amp;gt;adb_open()                      -&amp;gt;gadget_dev_desc_UDC_store()
   -&amp;gt;adb_write()                     -&amp;gt;usb_gadget_register_driver_owner
                                      -&amp;gt;driver_register()
-&amp;gt;StartMonitor()                       -&amp;gt;bus_add_driver()
 -&amp;gt;adb_read()                           -&amp;gt;gadget_bind_driver()
&amp;lt;times-out without BIND event&amp;gt;           -&amp;gt;configfs_composite_bind()
                                          -&amp;gt;usb_add_function()
-&amp;gt;open_functionfs()                        -&amp;gt;ffs_func_bind()
 -&amp;gt;adb_open()                               -&amp;gt;functionfs_bind()
                                       &amp;lt;ffs-&amp;gt;state !=FFS_ACTIVE&amp;gt;&lt;/p&gt;
&lt;p&gt;The adb_open, adb_read, and adb_write operations are invoked from the
daemon, but trying to bind the function is a process that is invoked by
UDC write through configfs, which opens up the possibility of a race
condition between the two paths. In this race scenario, the kernel panic
occurs due to the WARN…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-57913</guid>
    </item>
  </channel>
</rss>
