Description
In the Linux kernel, the following vulnerability has been resolved: net: usb: smsc95xx: Limit packet length to skb->len Packet length retrieved from descriptor may be larger than the actual socket buffer length. In such case the cloned skb passed up the network stack will leak kernel memory contents.
Product status
2f7ca802bdae2ca41022618391c70c2876d92190 (git) before 733580e268a53db1cd01f2251419da91866378f6
2f7ca802bdae2ca41022618391c70c2876d92190 (git) before d3c145a4d24b752c9a1314d5a595014d51471418
2f7ca802bdae2ca41022618391c70c2876d92190 (git) before f2111c791d885211714db85f9a06188571c57dd0
2f7ca802bdae2ca41022618391c70c2876d92190 (git) before 33d1603a38e05886c538129ddfe00bd52d347e7b
2f7ca802bdae2ca41022618391c70c2876d92190 (git) before ba6c40227108f8ee428e42eb0337b48ed3001e65
2f7ca802bdae2ca41022618391c70c2876d92190 (git) before e041bef1adee02999cf24f9a2e15ed452bc363fe
2f7ca802bdae2ca41022618391c70c2876d92190 (git) before 70eb25c6a6cde149affe8a587371a3a8ad295ba0
2f7ca802bdae2ca41022618391c70c2876d92190 (git) before ff821092cf02a70c2bccd2d19269f01e29aa52cf
2.6.28
Any version before 2.6.28
4.14.312 (semver)
4.19.280 (semver)
5.4.240 (semver)
5.10.177 (semver)
5.15.105 (semver)
6.1.22 (semver)
6.2.9 (semver)
6.3 (original_commit_for_fix)
References
git.kernel.org/...c/733580e268a53db1cd01f2251419da91866378f6
git.kernel.org/...c/d3c145a4d24b752c9a1314d5a595014d51471418
git.kernel.org/...c/f2111c791d885211714db85f9a06188571c57dd0
git.kernel.org/...c/33d1603a38e05886c538129ddfe00bd52d347e7b
git.kernel.org/...c/ba6c40227108f8ee428e42eb0337b48ed3001e65
git.kernel.org/...c/e041bef1adee02999cf24f9a2e15ed452bc363fe
git.kernel.org/...c/70eb25c6a6cde149affe8a587371a3a8ad295ba0
git.kernel.org/...c/ff821092cf02a70c2bccd2d19269f01e29aa52cf