CVE-2023-53068

net: usb: lan78xx: Limit packet length to skb->len

References

Notes

 carnil> Introduced in 55d7de9de6c3 ("Microchip's LAN7800 family USB 2/3 to 10/100/1000
 carnil> Ethernet device driver"). Vulnerable versions: 4.3.

Bugs

Status

Branch Status
upstream released (6.3-rc4) [7f247f5a2c18b3f21206cdd51193df4f38e1b9f5]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.14-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.6-upstream-stable N/A "Fixed before branching point"
6.1-upstream-stable released (6.1.22) [83de34967473ed31d276381373713cc2869a42e5]
5.10-upstream-stable needed
sid released (6.1.25-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security N/A "Fixed before branching point"
5.10-bullseye-security needed