Junglewise Threat Intelligence

CVE-2026-23447: Linux Linux kernel out-of-bounds read in cdc_ncm_rx_verify_ndp32

CVE-2026-23447 · Severity: high · CVSS 7.8 · Published 2026-04-03

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB networking driver could allow a local attacker to cause a system crash or potentially access sensitive information. The issue occurs when the system processes specifically formatted network data from a USB device. This could impact the stability and security of systems using certain USB Ethernet or tethering adapters.

Technical details

An out-of-bounds read vulnerability exists in the cdc_ncm_rx_verify_ndp32() function within drivers/net/usb/cdc_ncm.c of the Linux kernel. The root cause is an improper validation of the Datagram Pointer Entry (DPE) array size, which fails to account for the 'ndpoffset' when performing bounds checks against the total socket buffer (skb) length. A local attacker can exploit this by placing an NDP32 structure near the end of a Network Transfer Block (NTB), leading to out-of-bounds memory access. This can result in a denial of service (system crash) or information disclosure. Patches have been released for various stable kernel branches.

Affected products

  • Linux Linux 5.7 to 6.18.20

Timeline

  • 2026-03-13: other: Patch authored
  • 2026-04-03: advisory: Vulnerability published

References