« Volver al listado

CVE-2023-54110

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

usb: rndis_host: Secure rndis_query check against int overflow

Variables off and len typed as uint32 in rndis_query function are controlled by incoming RNDIS response message thus their value may be manipulated. Setting off to a unexpectetly large value will cause the sum with len and 8 to overflow and pass the implemented validation step. Consequently the response pointer will be referring to a location past the expected buffer boundaries allowing information leakage e.g. via RNDIS_OID_802_3_PERMANENT_ADDRESS OID.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54110",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ddda08624013e8435e9f7cfc34a35bd7b3520b6d",
              "lessThan": "55782f6d63a5a3dd3b84c1e0627738fc5b146b4e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddda08624013e8435e9f7cfc34a35bd7b3520b6d",
              "lessThan": "02ffb4ecf0614c58e3d0e5bfbe99588c9ddc77c0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddda08624013e8435e9f7cfc34a35bd7b3520b6d",
              "lessThan": "ebe6d2fcf7835f98cdbb1bd5e0414be20c321578",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddda08624013e8435e9f7cfc34a35bd7b3520b6d",
              "lessThan": "232ef345e5d76e5542f430a29658a85dbef07f0b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddda08624013e8435e9f7cfc34a35bd7b3520b6d",
              "lessThan": "11cd4ec6359d90b13ffb8f85a9df8637f0cf8d95",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddda08624013e8435e9f7cfc34a35bd7b3520b6d",
              "lessThan": "39eadaf5611ddd064ad1c53da65c02d2b0fe22a4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddda08624013e8435e9f7cfc34a35bd7b3520b6d",
              "lessThan": "a713602807f32afc04add331410c77ef790ef77a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ddda08624013e8435e9f7cfc34a35bd7b3520b6d",
              "lessThan": "c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/usb/rndis_host.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.22"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.22",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.14.303",
              "versionType": "semver",
              "lessThanOrEqual": "4.14.*"
            },
            {
              "status": "unaffected",
              "version": "4.19.270",
              "versionType": "semver",
              "lessThanOrEqual": "4.19.*"
            },
            {
              "status": "unaffected",
              "version": "5.4.229",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.163",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.87",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.0.19",
              "versionType": "semver",
              "lessThanOrEqual": "6.0.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/usb/rndis_host.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-24T13:16:12.897",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/02ffb4ecf0614c58e3d0e5bfbe99588c9ddc77c0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/11cd4ec6359d90b13ffb8f85a9df8637f0cf8d95",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/232ef345e5d76e5542f430a29658a85dbef07f0b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/39eadaf5611ddd064ad1c53da65c02d2b0fe22a4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/55782f6d63a5a3dd3b84c1e0627738fc5b146b4e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a713602807f32afc04add331410c77ef790ef77a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c7dd13805f8b8fc1ce3b6d40f6aff47e66b72ad2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ebe6d2fcf7835f98cdbb1bd5e0414be20c321578",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: rndis_host: Secure rndis_query check against int overflow\n\nVariables off and len typed as uint32 in rndis_query function\nare controlled by incoming RNDIS response message thus their\nvalue may be manipulated. Setting off to a unexpectetly large\nvalue will cause the sum with len and 8 to overflow and pass\nthe implemented validation step. Consequently the response\npointer will be referring to a location past the expected\nbuffer boundaries allowing information leakage e.g. via\nRNDIS_OID_802_3_PERMANENT_ADDRESS OID."
    }
  ],
  "lastModified": "2026-06-17T06:46:49.123",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}