CVE-2022-48837
published 2024-07-16CVE-2022-48837: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: prevent integer overflow in rndis_set_response() If "BufOffset" is very…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: rndis: prevent integer overflow in rndis_set_response()
If "BufOffset" is very large the "BufOffset + 8" operation can have an
integer overflow.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.17.3-1 (bookworm) | linux 5.17.3-1 (bookworm) |
| linux | linux | >= 2724ebafda0a8df08a9cb91557d33226bee80f7b < df7e088d51cdf78b1a0bf1f3d405c2593295c7b0 | df7e088d51cdf78b1a0bf1f3d405c2593295c7b0 |
| linux | linux | >= 2da3b0ab54fb7f4d7c5a82757246d0ee33a47197 < 56b38e3ca4064041d93c1ca18828c8cedad2e16c | 56b38e3ca4064041d93c1ca18828c8cedad2e16c |
| linux | linux | >= 38ea1eac7d88072bbffb630e2b3db83ca649b826 < 65f3324f4b6fed78b8761c3b74615ecf0ffa81fa | 65f3324f4b6fed78b8761c3b74615ecf0ffa81fa |
| linux | linux | >= 4.14.267 < 4.14.273 | 4.14.273 |
| linux | linux | >= 4.19.230 < 4.19.236 | 4.19.236 |
| linux | linux | >= 4.9.302 < 4.9.308 | 4.9.308 |
| linux | linux | >= 4c22fbcef778badb00fb8bb9f409daa29811c175 < c7953cf03a26876d676145ce5d2ae6d8c9630b90 | c7953cf03a26876d676145ce5d2ae6d8c9630b90 |
| linux | linux | >= 5.10.101 < 5.10.108 | 5.10.108 |
| linux | linux | >= 5.15.24 < 5.15.31 | 5.15.31 |
| linux | linux | >= 5.16.10 < 5.16.17 | 5.16.17 |
| linux | linux | >= 5.4.180 < 5.4.187 | 5.4.187 |
| linux | linux | >= c9e952871ae47af784b4aef0a77db02e557074d6 < 21829376268397f9fd2c35cfa9135937b6aa3a1e | 21829376268397f9fd2c35cfa9135937b6aa3a1e |
| linux | linux | >= db9aaa3026298d652e98f777bc0f5756e2455dda < 138d4f739b35dfb40438a0d5d7054965763bfbe7 | 138d4f739b35dfb40438a0d5d7054965763bfbe7 |
| linux | linux | >= fb4ff0f96de37c44236598e8b53fe43b1df36bf3 < 28bc0267399f42f987916a7174e2e32f0833cc65 | 28bc0267399f42f987916a7174e2e32f0833cc65 |
| linux | linux | >= ff0a90739925734c91c7e39befe3f4378e0c1369 < 8b3e4d26bc9cd0f6373d0095b9ffd99e7da8006b | 8b3e4d26bc9cd0f6373d0095b9ffd99e7da8006b |
| linux | linux_kernel | >= 0 < 5.10.113-1 | 5.10.113-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 0 < 5.17.3-1 | 5.17.3-1 |
| linux | linux_kernel | >= 4.14.267 < 4.14.273 | 4.14.273 |
| linux | linux_kernel | >= 4.19.230 < 4.19.236 | 4.19.236 |
| linux | linux_kernel | >= 4.9.302 < 4.9.308 | 4.9.308 |
| linux | linux_kernel | >= 5.10.101 < 5.10.108 | 5.10.108 |
| linux | linux_kernel | >= 5.15.24 < 5.15.31 | 5.15.31 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gq7q-6p5c-gpcc: In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: rndis: prevent integer overflow in rndis_set_response()
If "BufOffs
ghsa_unreviewed·2024-07-16
CVE-2022-48837 [HIGH] CWE-190 GHSA-gq7q-6p5c-gpcc: In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: rndis: prevent integer overflow in rndis_set_response()
If "BufOffs
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: rndis: prevent integer overflow in rndis_set_response()
If "BufOffset" is very large the "BufOffset + 8" operation can have an
integer overflow.
OSV
CVE-2022-48837: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: prevent integer overflow in rndis_set_response() If "BufOffset
osv·2024-07-16·CVSS 7.8
CVE-2022-48837 [HIGH] CVE-2022-48837: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: prevent integer overflow in rndis_set_response() If "BufOffset
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: prevent integer overflow in rndis_set_response() If "BufOffset" is very large the "BufOffset + 8" operation can have an integer overflow.
Red Hat
kernel: usb: gadget: rndis: prevent integer overflow in rndis_set_response()
vendor_redhat·2024-07-16·CVSS 7.8
CVE-2022-48837 [HIGH] kernel: usb: gadget: rndis: prevent integer overflow in rndis_set_response()
kernel: usb: gadget: rndis: prevent integer overflow in rndis_set_response()
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: rndis: prevent integer overflow in rndis_set_response()
If "BufOffset" is very large the "BufOffset + 8" operation can have an
integer overflow.
A possible integer overflow was found in the Linux kernel in rndis_set_response(). This may lead to a crash.
Statement: Red Hat Product Security has decided to rate this potential vulnerability as Moderate. Red Hat has protection mechanisms in place against buffer overflows, such as FORTIFY_SOURCE, Position Independent Executables or Stack Smashing Protection.
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support
Debian
CVE-2022-48837: linux - In the Linux kernel, the following vulnerability has been resolved: usb: gadget...
vendor_debian·2022·CVSS 7.8
CVE-2022-48837 [HIGH] CVE-2022-48837: linux - In the Linux kernel, the following vulnerability has been resolved: usb: gadget...
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: prevent integer overflow in rndis_set_response() If "BufOffset" is very large the "BufOffset + 8" operation can have an integer overflow.
Scope: local
bookworm: resolved (fixed in 5.17.3-1)
bullseye: resolved (fixed in 5.10.113-1)
forky: resolved (fixed in 5.17.3-1)
sid: resolved (fixed in 5.17.3-1)
trixie: resolved (fixed in 5.17.3-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.kernel.org/stable/c/138d4f739b35dfb40438a0d5d7054965763bfbe7https://git.kernel.org/stable/c/21829376268397f9fd2c35cfa9135937b6aa3a1ehttps://git.kernel.org/stable/c/28bc0267399f42f987916a7174e2e32f0833cc65https://git.kernel.org/stable/c/56b38e3ca4064041d93c1ca18828c8cedad2e16chttps://git.kernel.org/stable/c/65f3324f4b6fed78b8761c3b74615ecf0ffa81fahttps://git.kernel.org/stable/c/8b3e4d26bc9cd0f6373d0095b9ffd99e7da8006bhttps://git.kernel.org/stable/c/c7953cf03a26876d676145ce5d2ae6d8c9630b90https://git.kernel.org/stable/c/df7e088d51cdf78b1a0bf1f3d405c2593295c7b0https://git.kernel.org/stable/c/138d4f739b35dfb40438a0d5d7054965763bfbe7https://git.kernel.org/stable/c/21829376268397f9fd2c35cfa9135937b6aa3a1ehttps://git.kernel.org/stable/c/28bc0267399f42f987916a7174e2e32f0833cc65https://git.kernel.org/stable/c/56b38e3ca4064041d93c1ca18828c8cedad2e16chttps://git.kernel.org/stable/c/65f3324f4b6fed78b8761c3b74615ecf0ffa81fahttps://git.kernel.org/stable/c/8b3e4d26bc9cd0f6373d0095b9ffd99e7da8006bhttps://git.kernel.org/stable/c/c7953cf03a26876d676145ce5d2ae6d8c9630b90https://git.kernel.org/stable/c/df7e088d51cdf78b1a0bf1f3d405c2593295c7b0
2024-07-16
Published