Clone
Lucas Holt
committed
on 15 Sep
A programming error in the ure(4) device driver caused some Realtek USB Ethernet interfaces to incorrectly report packets with more than 204… Show more
A programming error in the ure(4) device driver caused some Realtek USB Ethernet interfaces to incorrectly report packets with more than 2048 bytes in a single USB transfer as having a length of only 2048 bytes.

An adversary can exploit this to cause the driver to misinterpret part of the

payload of a large packet as a separate packet, and thereby inject packets

across security boundaries such as VLANs.

Show less