CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2024-58006: PCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()

mediumCVSS 5.5CVE-2024-58006

CSIRTS triage

What
The PCI DWC endpoint driver allows BAR size and flags to be modified after initial configuration, potentially compromising security.
Who is affected
Systems using the DWC PCI endpoint controller driver.
Urgency
Medium priority; not currently exploited but affects PCI security boundary enforcement.
Action
Update the Linux kernel to prevent BAR size and flags modification in pci_epc_set_bar().

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch dwc

Get an email when a new dwc advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
medium — CVSS 5.5
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-58006

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2024-58006coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Microsoft Security Response Center