Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-23559


In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.


Published

2023-01-13T01:15:10.300

Last Modified

2025-05-05T16:15:30.147

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-190
  • Type: Secondary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel < 4.14.305 Yes
Operating System linux linux_kernel < 4.19.272 Yes
Operating System linux linux_kernel < 5.4.231 Yes
Operating System linux linux_kernel < 5.10.166 Yes
Operating System linux linux_kernel < 5.15.91 Yes
Operating System linux linux_kernel < 6.1.9 Yes
Application netapp hci_baseboard_management_controller h300s Yes
Application netapp hci_baseboard_management_controller h410c Yes
Application netapp hci_baseboard_management_controller h410s Yes
Application netapp hci_baseboard_management_controller h500s Yes
Application netapp hci_baseboard_management_controller h700s Yes
Operating System debian debian_linux 10.0 Yes

References