An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.
References
Configurations
History
No history.
Information
Published : 2022-02-20 20:15
Updated : 2024-11-21 06:52
NVD link : CVE-2022-25375
Mitre link : CVE-2022-25375
CVE.ORG link : CVE-2022-25375
JSON object : View
Products Affected
linux
- linux_kernel
debian
- debian_linux
CWE
CWE-1284
Improper Validation of Specified Quantity in Input