Description
An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.
Exploits (1)
References (8)
Scores
CVSS v3
5.5
EPSS
0.0071
EPSS Percentile
72.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-1284
Status
published
Products (4)
debian/debian_linux
9.0
debian/debian_linux
10.0
debian/debian_linux
11.0
linux/linux_kernel
< 5.16.10
Published
Feb 20, 2022
Tracked Since
Feb 18, 2026