CVE-2022-49398

usb: dwc3: gadget: Replace list_for_each_entry_safe() if using giveback

References

Notes

 carnil> Introduced in d4f1afe5e896 ("usb: dwc3: gadget: move requests to
 carnil> cancelled_list"). Vulnerable versions: 4.19.57 5.0-rc1.

Bugs

Status

Branch Status
upstream released (5.19-rc1) [bf594d1d0c1d7b895954018043536ffd327844f9]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.13-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.6-upstream-stable N/A "Fixed before branching point"
6.1-upstream-stable N/A "Fixed before branching point"
5.10-upstream-stable needed
sid released (5.18.5-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security N/A "Fixed before branching point"
5.10-bullseye-security needed