CVE-2022-25375

MEDIUM

Linux kernel <5.16.10 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-25375. PoCs published by szymonh.

AI-analyzed exploit summary This PoC exploits CVE-2022-25375, an information leak vulnerability in the Linux RNDIS USB gadget driver. It manipulates the InformationBufferOffset to read kernel memory by setting and querying the packet filter OID.

Description

An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory.

Exploits (1)

nomisec WORKING POC 8 stars
by szymonh · poc
https://github.com/szymonh/rndis-co

This PoC exploits CVE-2022-25375, an information leak vulnerability in the Linux RNDIS USB gadget driver. It manipulates the InformationBufferOffset to read kernel memory by setting and querying the packet filter OID.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Linux kernel RNDIS USB gadget (pre-5.16.10)
No auth needed
Prerequisites: Physical or logical access to a USB RNDIS gadget interface · pyusb library
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Patch, Release Notes, Vendor Advisory x_refsource_misc
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.16.10
Third Party Advisory x_refsource_misc
https://github.com/szymonh/rndis-co
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/02/21/1
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2022/dsa-5092
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/03/msg00011.html
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2022/dsa-5096

Scores

CVSS v3 5.5
EPSS 0.0105
EPSS Percentile 59.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-1284
Status published
Products (4)
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
linux/linux_kernel < 5.16.10
Published Feb 20, 2022
Tracked Since Feb 18, 2026