PT-2023-35234 · Linux · Linux Kernel

Published

2023-02-13

·

Updated

2023-02-13

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux Kernel versions 2.6.35 through 5.10.165
Description A buffer overflow issue exists in the rndis wlan component of the Linux Kernel, specifically in the rndis query oid function. This issue was introduced in version v2.6.35 and is fixed in version v5.10.166. The actual impact and attack plausibility have not yet been proven.
Recommendations For Linux Kernel versions 2.6.35 through 5.10.165, update to version v5.10.166 or later to resolve the issue. As a temporary workaround, consider restricting access to the rndis query oid function until a patch is available.

Related Identifiers

GSD-2023-1002158

Affected Products

Linux Kernel