A vulnerability exists in the Linux kernel's RNDIS USB gadget implementation (drivers/usb/gadget/function/rndis.c) prior to version 5.16.10, where the RNDIS_MSG_SET command does not properly validate the size of incoming messages. This lack of validation allows attackers to craft specially formed RNDIS_MSG_SET commands that can trigger the kernel to disclose sensitive information from kernel memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept exploit (rndisco.py) for CVE-2022-25375, a vulnerability in the Linux USB RNDIS gadget implementation. The exploit leverages improper bounds checking in the RNDIS_MSG_SET handler, allowing an attacker to manipulate the InformationBufferOffset and read arbitrary kernel memory via USB control transfers. The Python script uses the pyusb library to communicate with a vulnerable device, repeatedly setting and querying the RNDIS packet filter to extract memory two bytes at a time. The README provides a detailed technical explanation of the vulnerability, exploitation method, and impact. The exploit requires the attacker to know the target device's USB Vendor ID and Product ID and to have access to the USB interface. The repository is structured simply, with the main exploit logic in rndisco.py, a README with technical details and usage instructions, and standard license and gitignore files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.