cbcvebase.
CVE-2023-23559
published 2023-01-13

CVE-2023-23559: In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.11-1 (bookworm)linux 6.1.11-1 (bookworm)
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 6.1.11-16.1.11-1
linuxlinux_kernel>= 0 < 4.15.0-208.2204.15.0-208.220
linuxlinux_kernel>= 0 < 5.4.0-146.1635.4.0-146.163
linuxlinux_kernel>= 0 < 5.15.0-69.765.15.0-69.76
linuxlinux_kernel>= 0 < 4.4.0-237.2714.4.0-237.271
linuxlinux_kernel>= 2.6.35 < 4.14.3054.14.305
linuxlinux_kernel>= 4.15 < 4.19.2724.19.272
linuxlinux_kernel>= 4.20 < 5.4.2315.4.231
linuxlinux_kernel>= 5.11 < 5.15.915.15.91
linuxlinux_kernel>= 5.16 < 6.1.96.1.9
linuxlinux_kernel>= 5.5 < 5.10.1665.10.166
msrccbl2_kernel_5.15.92.1-1_on_cbl_mariner_2.0
msrccm1_kernel_5.10.168.1-1_on_cbl_mariner_1.0
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller
netapphci_baseboard_management_controller

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH