rndis_host: add overflow check in rndis_rx_fixup()
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
rndis_host: add overflow check in rndis_rx_fixup()
Add an overflow check to ensure that data_offset + data_len + 8 does not
wrap, which would enable an OOB read of the USB data buffer.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/10a6b99079697c5027b25352e882bdf54fef702ahttps://git.kernel.org/stable/c/2140db1232af04b92faa6c4a2a40df6371ea89ffhttps://git.kernel.org/stable/c/2ded89ca77fae1da6886fe94831acfe4d6aa80b1https://git.kernel.org/stable/c/8ca3bd404d076495ed0b274b65971c57b6fd5ac0https://git.kernel.org/stable/c/965a251f23ff69cfb4486974d4532e9bb551c7fchttps://git.kernel.org/stable/c/be7dc3650f799a253df4edd4fe230fc9ea4be063https://git.kernel.org/stable/c/c5398ce6db7647b7004d73a3102ccc25fb4bb596https://git.kernel.org/stable/c/e971d956353d382ee2185d71c47b538501a43f76https://git.kernel.org/stable/c/f8e6fde5db87f855e99b200e392467274f0eb9d7