Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-23559

Опубликовано: 10 янв. 2023
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.

An integer overflow flaw was found in the Linux kernel’s wireless RNDIS USB device driver in how a user installs a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.

Отчет

This issue is rated Moderate, because the bug is initiated by incorrect data from the USB device (and the user cannot control it until they can insert or emulate a malicious USB device). The attack complexity high and some privileges required, so it should be considered Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 9kernelNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2170114kernel: Integer overflow in function rndis_query_oid of rndis_wlan.c

EPSS

Процентиль: 5%
0.00023
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.

CVSS3: 7.8
nvd
почти 3 года назад

In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.

CVSS3: 7.8
msrc
почти 3 года назад

In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5 there is an integer overflow in an addition.

CVSS3: 7.8
debian
почти 3 года назад

In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux k ...

CVSS3: 7.8
github
почти 3 года назад

In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.

EPSS

Процентиль: 5%
0.00023
Низкий

7 High

CVSS3