cbcvebase.
CVE-2023-54110
published 2025-12-24

CVE-2023-54110: In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and len typed…

PriorityP424medium6.7
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and len typed as uint32 in rndis_query function are controlled by incoming RNDIS response message thus their value may be manipulated. Setting off to a unexpectetly large value will cause the sum with len and 8 to overflow and pass the implemented validation step. Consequently the response pointer will be referring to a location past the expected buffer boundaries allowing information leakage e.g. via RNDIS_OID_802_3_PERMANENT_ADDRESS OID.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.7-1 (bookworm)linux 6.1.7-1 (bookworm)
linuxlinux
linuxlinux>= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 55782f6d63a5a3dd3b84c1e0627738fc5b146b4e55782f6d63a5a3dd3b84c1e0627738fc5b146b4e
linuxlinux>= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 02ffb4ecf0614c58e3d0e5bfbe99588c9ddc77c002ffb4ecf0614c58e3d0e5bfbe99588c9ddc77c0
linuxlinux>= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < ebe6d2fcf7835f98cdbb1bd5e0414be20c321578ebe6d2fcf7835f98cdbb1bd5e0414be20c321578
linuxlinux>= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 232ef345e5d76e5542f430a29658a85dbef07f0b232ef345e5d76e5542f430a29658a85dbef07f0b
linuxlinux>= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 11cd4ec6359d90b13ffb8f85a9df8637f0cf8d9511cd4ec6359d90b13ffb8f85a9df8637f0cf8d95
linuxlinux>= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 39eadaf5611ddd064ad1c53da65c02d2b0fe22a439eadaf5611ddd064ad1c53da65c02d2b0fe22a4
linuxlinux>= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < a713602807f32afc04add331410c77ef790ef77aa713602807f32afc04add331410c77ef790ef77a
linuxlinux>= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2
linuxlinux_kernel>= 0 < 5.10.178-15.10.178-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 0 < 6.1.7-16.1.7-1
linuxlinux_kernel>= 2.6.22 < 4.14.3034.14.303
linuxlinux_kernel>= 4.15.0 < 4.19.2704.19.270
linuxlinux_kernel>= 4.20.0 < 5.4.2295.4.229
linuxlinux_kernel>= 5.11.0 < 5.15.875.15.87
linuxlinux_kernel>= 5.16.0 < 6.0.196.0.19
linuxlinux_kernel>= 5.5.0 < 5.10.1635.10.163
linuxlinux_kernel>= 6.1.0 < 6.1.56.1.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.