CVE-2006-1368

Linux kernel <2.6.16 - Buffer Overflow

Title source: llm

Description

Buffer overflow in the USB Gadget RNDIS implementation in the Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (kmalloc'd memory corruption) via a remote NDIS response to OID_GEN_SUPPORTED_LIST, which causes memory to be allocated for the reply data but not the reply structure.

Scores

EPSS 0.0310
EPSS Percentile 86.6%

Classification

CWE
CWE-119
Status draft

Affected Products (1)

linux/linux_kernel < 2.6.15

Timeline

Published Mar 23, 2006
Tracked Since Feb 18, 2026