A vulnerability marked as very critical has been reported in Linux Kernel up to 7.2-rc2. This affects the function rndis_query_response of the component rndis. This manipulation of the argument BufLength/BufOffset causes buffer overflow.

This vulnerability appears as CVE-2026-68088. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.