CVE-2023-54110
Last modified
CVE-2023-54110 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and len typed as uint32 in rndis_query function are controlled by incoming RNDIS response message thus their value may be manipulated. Setting off to a unexpectetly large value will cause the sum with len and 8 to overflow and pass the implemented validation step. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: usb: rndis_host: Secure rndis_query check against int overflow Variables off and len typed as uint32 in rndis_query function are controlled by incoming RNDIS response message thus their value may be manipulated. Setting off to a unexpectetly large value will cause the sum with len and 8 to overflow and pass the implemented validation step. Consequently the response pointer will be referring to a location past the expected buffer boundaries allowing information leakage e.g. via RNDIS_OID_802_3_PERMANENT_ADDRESS OID.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d, < 55782f6d63a5a3dd3b84c1e0627738fc5b146b4e; >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d, < 02ffb4ecf0614c58e3d0e5bfbe99588c9ddc77c0; >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d, < ebe6d2fcf7835f98cdbb1bd5e0414be20c321578; >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d, < 232ef345e5d76e5542f430a29658a85dbef07f0b; >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d, < 11cd4ec6359d90b13ffb8f85a9df8637f0cf8d95; >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d, < 39eadaf5611ddd064ad1c53da65c02d2b0fe22a4; >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d, < a713602807f32afc04add331410c77ef790ef77a; >= ddda08624013e8435e9f7cfc34a35bd7b3520b6d, < c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2 |
| Linux | Linux | 2.6.22 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2023-54110?
How severe is CVE-2023-54110?
How do I fix CVE-2023-54110?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-54105In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54106In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54107In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2023-54108In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54109In the Linux kernel, the following vulnerability has been re…
- CVE-2023-5411The Funnelforms Free plugin for WordPress is vulnerable to u…4.3
- CVE-2023-54111In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54112In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54113In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54114In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54115In the Linux kernel, the following vulnerability has been re…
- CVE-2023-54116In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2023-54110?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
