Junglewise Threat Intelligence

CVE-2026-23448: Linux Kernel out-of-bounds read in cdc_ncm USB driver

CVE-2026-23448 · Severity: high · CVSS 7.8 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's USB networking driver could allow a local attacker to cause a system crash or potentially access sensitive information. The issue occurs when the system processes specifically formatted network data from a USB device, leading to an out-of-bounds memory read. This affects systems using the CDC NCM protocol, commonly used for mobile broadband and Ethernet-over-USB connections.

Technical details

An out-of-bounds read vulnerability exists in the cdc_ncm_rx_verify_ndp16() function within the Linux kernel's USB networking subsystem. The root cause is an improper bounds check where the code fails to account for the 'ndpoffset' when validating the size of the Datagram Pointer Entry (DPE) array against the socket buffer (skb) length. When a Network Data Pointer (NDP) is positioned near the end of a Network Transfer Block (NTB), an attacker can trigger a read past the end of the skb data buffer during DPE array iteration in cdc_ncm_rx_fixup(). This is classified as CWE-129 (Improper Validation of Array Index). Patches have been released for multiple stable kernel branches including 6.6.y, 6.12.y, 6.18.y, and 6.19.y.

Affected products

  • Linux Linux Kernel 3.8 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10, 7.0-rc1 to 7.0-rc4

Timeline

  • 2026-03-13: other: Patch authored
  • 2026-04-03: disclosed: CVE published
  • 2026-05-20: advisory: NVD analysis completed

References