CVE-2026-23447: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
In the Linux kernel, the following vulnerability has been resolved:
net: usb: cdcncm: add ndpoffset to NDP32 nframes bounds check
The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdcncmrxverifyndp32(). The DPE array size is validated against the total skb length without accounting for ndpoffset, allowing out-of-bounds reads when the NDP32 is placed near the end of the NTB.
Add ndpoffset to the nframes bounds check and use structsizet() to express the NDP-plus-DPE-array size more clearly.
Compile-tested only.
Affected Software
Event History
Frequently Asked Questions
What level of attacker access is required?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
Which systems are exposed to this issue?
The affected code is in the Linux kernel's net/usb/cdc_ncm component. Exposure is limited to systems that use this CDC NCM USB networking receive path, specifically NDP32 frame handling.