Description
In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages3 packages
▶Debianlinux< 5.10.178-1+3 Also affects: Debian Linux 10.0
🔴Vulnerability Details
3GHSAGHSA-mjh5-rrhw-qhv4: In rndis_query_oid in drivers/net/wireless/rndis_wlan↗2023-01-13 ▶ OSVCVE-2023-23559: In rndis_query_oid in drivers/net/wireless/rndis_wlan↗2023-01-13 ▶ CVEListCVE-2023-23559: In rndis_query_oid in drivers/net/wireless/rndis_wlan↗2023-01-13 ▶ 📋Vendor Advisories
23UbuntuLinux kernel (Xilinx ZynqMP) vulnerabilities↗2023-06-08 ▶ UbuntuLinux kernel (OEM) vulnerabilities↗2023-04-19 ▶ UbuntuLinux kernel (Qualcomm Snapdragon) vulnerabilities↗2023-04-19 ▶ UbuntuLinux kernel (OEM) vulnerabilities↗2023-04-19 ▶ UbuntuLinux kernel (BlueField) vulnerabilities↗2023-04-14 ▶