CVE-2022-48837 - CVE House
Back to Database
Status published High CVE-2022-48837

usb: gadget: rndis: prevent integer overflow in rndis_set_response()

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: prevent integer overflow in rndis_set_response() If "BufOffset" is very large the "BufOffset + 8" operation can have an integer overflow.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-48837

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
ff0a90739925734c91c7e39befe3f4378e0c1369, 4c22fbcef778badb00fb8bb9f409daa29811c175, db9aaa3026298d652e98f777bc0f5756e2455dda, c9e952871ae47af784b4aef0a77db02e557074d6, fb4ff0f96de37c44236598e8b53fe43b1df36bf3, 2da3b0ab54fb7f4d7c5a82757246d0ee33a47197, 2724ebafda0a8df08a9cb91557d33226bee80f7b, 38ea1eac7d88072bbffb630e2b3db83ca649b826, 4.9.302, 4.14.267, 4.19.230, 5.4.180, 5.10.101, 5.15.24, 5.16.10

Timeline

Official Publish: July 16th, 2024
Last Modified: May 11th, 2026
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.