CVE-2023-54110
published 2025-12-24CVE-2023-54110: In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and len typed…
PriorityP424medium6.7
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved:
usb: rndis_host: Secure rndis_query check against int overflow
Variables off and len typed as uint32 in rndis_query function
are controlled by incoming RNDIS response message thus their
value may be manipulated. Setting off to a unexpectetly large
value will cause the sum with len and 8 to overflow and pass
the implemented validation step. Consequently the response
pointer will be referring to a location past the expected
buffer boundaries allowing information leakage e.g. via
RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.7-1 (bookworm) | linux 6.1.7-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 55782f6d63a5a3dd3b84c1e0627738fc5b146b4e | 55782f6d63a5a3dd3b84c1e0627738fc5b146b4e |
| linux | linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 02ffb4ecf0614c58e3d0e5bfbe99588c9ddc77c0 | 02ffb4ecf0614c58e3d0e5bfbe99588c9ddc77c0 |
| linux | linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < ebe6d2fcf7835f98cdbb1bd5e0414be20c321578 | ebe6d2fcf7835f98cdbb1bd5e0414be20c321578 |
| linux | linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 232ef345e5d76e5542f430a29658a85dbef07f0b | 232ef345e5d76e5542f430a29658a85dbef07f0b |
| linux | linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 11cd4ec6359d90b13ffb8f85a9df8637f0cf8d95 | 11cd4ec6359d90b13ffb8f85a9df8637f0cf8d95 |
| linux | linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < 39eadaf5611ddd064ad1c53da65c02d2b0fe22a4 | 39eadaf5611ddd064ad1c53da65c02d2b0fe22a4 |
| linux | linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < a713602807f32afc04add331410c77ef790ef77a | a713602807f32afc04add331410c77ef790ef77a |
| linux | linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d < c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2 | c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2 |
| linux | linux_kernel | >= 0 < 5.10.178-1 | 5.10.178-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 0 < 6.1.7-1 | 6.1.7-1 |
| linux | linux_kernel | >= 2.6.22 < 4.14.303 | 4.14.303 |
| linux | linux_kernel | >= 4.15.0 < 4.19.270 | 4.19.270 |
| linux | linux_kernel | >= 4.20.0 < 5.4.229 | 5.4.229 |
| linux | linux_kernel | >= 5.11.0 < 5.15.87 | 5.15.87 |
| linux | linux_kernel | >= 5.16.0 < 6.0.19 | 6.0.19 |
| linux | linux_kernel | >= 5.5.0 < 5.10.163 | 5.10.163 |
| linux | linux_kernel | >= 6.1.0 < 6.1.5 | 6.1.5 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cffh-ppgh-4vqx: In the Linux kernel, the following vulnerability has been resolved:
usb: rndis_host: Secure rndis_query check against int overflow
Variables off and
ghsa_unreviewed·2025-12-24
CVE-2023-54110 GHSA-cffh-ppgh-4vqx: In the Linux kernel, the following vulnerability has been resolved:
usb: rndis_host: Secure rndis_query check against int overflow
Variables off and
In the Linux kernel, the following vulnerability has been resolved:
usb: rndis_host: Secure rndis_query check against int overflow
Variables off and len typed as uint32 in rndis_query function
are controlled by incoming RNDIS response message thus their
value may be manipulated. Setting off to a unexpectetly large
value will cause the sum with len and 8 to overflow and pass
the implemented validation step. Consequently the response
pointer will be referring to a location past the expected
buffer boundaries allowing information leakage e.g. via
RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
OSV
usb: rndis_host: Secure rndis_query check against int overflow
osv·2025-12-24
CVE-2023-54110 usb: rndis_host: Secure rndis_query check against int overflow
usb: rndis_host: Secure rndis_query check against int overflow
In the Linux kernel, the following vulnerability has been resolved:
usb: rndis_host: Secure rndis_query check against int overflow
Variables off and len typed as uint32 in rndis_query function
are controlled by incoming RNDIS response message thus their
value may be manipulated. Setting off to a unexpectetly large
value will cause the sum with len and 8 to overflow and pass
the implemented validation step. Consequently the response
pointer will be referring to a location past the expected
buffer boundaries allowing information leakage e.g. via
RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
OSV
CVE-2023-54110: In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and l
osv·2025-12-24
CVE-2023-54110 CVE-2023-54110: In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and l
In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and len typed as uint32 in rndis_query function are controlled by incoming RNDIS response message thus their value may be manipulated. Setting off to a unexpectetly large value will cause the sum with len and 8 to overflow and pass the implemented validation step. Consequently the response pointer will be referring to a location past the expected buffer boundaries allowing information leakage e.g. via RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
Red Hat
kernel: usb: rndis_host: Secure rndis_query check against int overflow
vendor_redhat·2025-12-24·CVSS 6.7
CVE-2023-54110 [MEDIUM] CWE-190 kernel: usb: rndis_host: Secure rndis_query check against int overflow
kernel: usb: rndis_host: Secure rndis_query check against int overflow
In the Linux kernel, the following vulnerability has been resolved:
usb: rndis_host: Secure rndis_query check against int overflow
Variables off and len typed as uint32 in rndis_query function
are controlled by incoming RNDIS response message thus their
value may be manipulated. Setting off to a unexpectetly large
value will cause the sum with len and 8 to overflow and pass
the implemented validation step. Consequently the response
pointer will be referring to a location past the expected
buffer boundaries allowing information leakage e.g. via
RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Under investigation
Package:
Debian
CVE-2023-54110: linux - In the Linux kernel, the following vulnerability has been resolved: usb: rndis_...
vendor_debian·2023
CVE-2023-54110 CVE-2023-54110: linux - In the Linux kernel, the following vulnerability has been resolved: usb: rndis_...
In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and len typed as uint32 in rndis_query function are controlled by incoming RNDIS response message thus their value may be manipulated. Setting off to a unexpectetly large value will cause the sum with len and 8 to overflow and pass the implemented validation step. Consequently the response pointer will be referring to a location past the expected buffer boundaries allowing information leakage e.g. via RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
Scope: local
bookworm: resolved (fixed in 6.1.7-1)
bullseye: resolved (fixed in 5.10.178-1)
forky: resolved (fixed in 6.1.7-1)
sid: resolved (fixed in 6.1.7-1)
trixie: resolved (fixed in 6.1.7-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54110 kernel: usb: rndis_host: Secure rndis_query check against int overflow
bugzilla·2025-12-24
CVE-2023-54110 [MEDIUM] CVE-2023-54110 kernel: usb: rndis_host: Secure rndis_query check against int overflow
CVE-2023-54110 kernel: usb: rndis_host: Secure rndis_query check against int overflow
In the Linux kernel, the following vulnerability has been resolved:
usb: rndis_host: Secure rndis_query check against int overflow
Variables off and len typed as uint32 in rndis_query function
are controlled by incoming RNDIS response message thus their
value may be manipulated. Setting off to a unexpectetly large
value will cause the sum with len and 8 to overflow and pass
the implemented validation step. Consequently the response
pointer will be referring to a location past the expected
buffer boundaries allowing information leakage e.g. via
RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122413-CVE-2023-54110-5816@gregkh/T
Wiz
CVE-2023-54110 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54110 CVE-2023-54110 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54110 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
usb: rndis_host: Secure rndis_query check against int overflow
Variables off and len typed as uint32 in rndis_query function
are controlled by incoming RNDIS response message thus their
value may be manipulated. Setting off to a unexpectetly large
value will cause the sum with len and 8 to overflow and pass
the implemented validation step. Consequently the response
pointer will be referring to a location past the expected
buffer boundaries allowing information leakage e.g. via
RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
Source : NVD
Published December 24, 2025
CNA Score N/A
Affected Technologies
Linux Kernel
Linux Debian
Has Public Exploit No
Has
https://git.kernel.org/stable/c/02ffb4ecf0614c58e3d0e5bfbe99588c9ddc77c0https://git.kernel.org/stable/c/11cd4ec6359d90b13ffb8f85a9df8637f0cf8d95https://git.kernel.org/stable/c/232ef345e5d76e5542f430a29658a85dbef07f0bhttps://git.kernel.org/stable/c/39eadaf5611ddd064ad1c53da65c02d2b0fe22a4https://git.kernel.org/stable/c/55782f6d63a5a3dd3b84c1e0627738fc5b146b4ehttps://git.kernel.org/stable/c/a713602807f32afc04add331410c77ef790ef77ahttps://git.kernel.org/stable/c/c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2https://git.kernel.org/stable/c/ebe6d2fcf7835f98cdbb1bd5e0414be20c321578
2025-12-24
Published