Description
In the Linux kernel, the following vulnerability has been resolved: usb: net: sierra: check for no status endpoint The driver checks for having three endpoints and having bulk in and out endpoints, but not that the third endpoint is interrupt input. Rectify the omission.
Product status
eb4fd8cd355c8ec425a12ec6cbdac614e8a4819d (git) before 0a263ccb905b4ae2af381cd4280bd8d2477b98b8
eb4fd8cd355c8ec425a12ec6cbdac614e8a4819d (git) before 5408cc668e596c81cdd29e137225432aa40d1785
eb4fd8cd355c8ec425a12ec6cbdac614e8a4819d (git) before a6a238c4126eb3ddb495d3f960193ca5bb778d92
eb4fd8cd355c8ec425a12ec6cbdac614e8a4819d (git) before 5849980faea1c792d1d5e54fdbf1e69ac0a9bfb9
eb4fd8cd355c8ec425a12ec6cbdac614e8a4819d (git) before 5dd6a441748dad2f02e27b256984ca0b2d4546b6
eb4fd8cd355c8ec425a12ec6cbdac614e8a4819d (git) before 65c666aff44eb7f9079c55331abd9687fb77ba2d
eb4fd8cd355c8ec425a12ec6cbdac614e8a4819d (git) before bfe8ef373986e8f185d3d6613eb1801a8749837a
eb4fd8cd355c8ec425a12ec6cbdac614e8a4819d (git) before 4c4ca3c46167518f8534ed70f6e3b4bf86c4d158
2.6.34
Any version before 2.6.34
5.4.297 (semver)
5.10.241 (semver)
5.15.190 (semver)
6.1.147 (semver)
6.6.100 (semver)
6.12.40 (semver)
6.15.8 (semver)
6.16 (original_commit_for_fix)
References
lists.debian.org/debian-lts-announce/2025/10/msg00008.html
lists.debian.org/debian-lts-announce/2025/10/msg00007.html
git.kernel.org/...c/0a263ccb905b4ae2af381cd4280bd8d2477b98b8
git.kernel.org/...c/5408cc668e596c81cdd29e137225432aa40d1785
git.kernel.org/...c/a6a238c4126eb3ddb495d3f960193ca5bb778d92
git.kernel.org/...c/5849980faea1c792d1d5e54fdbf1e69ac0a9bfb9
git.kernel.org/...c/5dd6a441748dad2f02e27b256984ca0b2d4546b6
git.kernel.org/...c/65c666aff44eb7f9079c55331abd9687fb77ba2d
git.kernel.org/...c/bfe8ef373986e8f185d3d6613eb1801a8749837a
git.kernel.org/...c/4c4ca3c46167518f8534ed70f6e3b4bf86c4d158