CVE-2022-48837: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: prevent integer overflow in rndis_set_response() If "BufOffset" is very large the "BufOffset + 8" operation can have an integer overflow.

Affected products

  • Linux Linux Kernel: from 4.9.302, before 4.9.308 (fixed in 4.9.308); from 4.14.267, before 4.14.273 (fixed in 4.14.273); from 4.19.230, before 4.19.236 (fixed in 4.19.236); from 5.4.180, before 5.4.187 (fixed in 5.4.187); from 5.10.101, before 5.10.108 (fixed in 5.10.108); from 5.15.24, before 5.15.31 (fixed in 5.15.31); …

Published 2024-07-16. Last modified 2026-06-17.