{"id":"DEBIAN-CVE-2024-56670","details":"In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer  Considering that in some extreme cases, when u_serial driver is accessed by multiple threads, Thread A is executing the open operation and calling the gs_open, Thread B is executing the disconnect operation and calling the gserial_disconnect function,The port-\u003eport_usb pointer will be set to NULL.  E.g.     Thread A                                 Thread B     gs_open()                                gadget_unbind_driver()     gs_start_io()                            composite_disconnect()     gs_start_rx()                            gserial_disconnect()     ...                                      ...     spin_unlock(&port-\u003eport_lock)     status = usb_ep_queue()                  spin_lock(&port-\u003eport_lock)     spin_lock(&port-\u003eport_lock)              port-\u003eport_usb = NULL     gs_free_requests(port-\u003eport_usb-\u003ein)     spin_unlock(&port-\u003eport_lock)     Crash  This causes thread A to access a null pointer (port-\u003eport_usb is null) when calling the gs_free_requests function, causing a crash.  If port_usb is NULL, the release request will be skipped as it will be done by gserial_disconnect.  So add a null pointer check to gs_start_io before attempting to access the value of the pointer port-\u003eport_usb.  Call trace:  gs_start_io+0x164/0x25c  gs_open+0x108/0x13c  tty_open+0x314/0x638  chrdev_open+0x1b8/0x258  do_dentry_open+0x2c4/0x700  vfs_open+0x2c/0x3c  path_openat+0xa64/0xc60  do_filp_open+0xb8/0x164  do_sys_openat2+0x84/0xf0  __arm64_sys_openat+0x70/0x9c  invoke_syscall+0x58/0x114  el0_svc_common+0x80/0xe0  do_el0_svc+0x1c/0x28  el0_svc+0x38/0x68","modified":"2026-09-15T09:03:17.189804592Z","published":"2024-12-27T15:15:26.890Z","upstream":["CVE-2024-56670"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-56670"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.123-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56670.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56670.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-56670.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}