In the Linux kernel, the following vulnerability has been resolved:
USB: usbtmc: prevent kernel-usb-infoleak
The syzbot reported a kernel-usb-infoleak in usbtmc_write, we need to clear the structure before filling fields.
{ "vanir_signatures": [ { "id": "CVE-2024-47671-de64aeff", "signature_type": "Line", "target": { "file": "drivers/usb/class/usbtmc.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "164562033608018208110796060903666983506", "219159230014852285622686777142612621690", "216976002817678238296238047650122246213", "286871514591919847757998033794939228549" ], "threshold": 0.9 }, "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@16e0ab9ed3ae7d19ca8ee718ba4e09d5c0f909ca" }, { "id": "CVE-2024-47671-feafda61", "signature_type": "Line", "target": { "file": "drivers/usb/class/usbtmc.c" }, "signature_version": "v1", "digest": { "line_hashes": [ "164562033608018208110796060903666983506", "219159230014852285622686777142612621690", "216976002817678238296238047650122246213", "286871514591919847757998033794939228549" ], "threshold": 0.9 }, "deprecated": false, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@625fa77151f00c1bd00d34d60d6f2e710b3f9aad" } ] }