Executive brief
A vulnerability in the Linux kernel's USB networking driver could allow a local attacker to cause a system crash or potentially access sensitive information. The issue occurs when the system processes specifically formatted network data from a USB device, leading to an out-of-bounds memory read. This affects systems using the CDC NCM protocol, commonly used for mobile broadband and Ethernet-over-USB connections.
Technical details
An out-of-bounds read vulnerability exists in the cdc_ncm_rx_verify_ndp16() function within the Linux kernel's USB networking subsystem. The root cause is an improper bounds check where the code fails to account for the 'ndpoffset' when validating the size of the Datagram Pointer Entry (DPE) array against the socket buffer (skb) length. When a Network Data Pointer (NDP) is positioned near the end of a Network Transfer Block (NTB), an attacker can trigger a read past the end of the skb data buffer during DPE array iteration in cdc_ncm_rx_fixup(). This is classified as CWE-129 (Improper Validation of Array Index). Patches have been released for multiple stable kernel branches including 6.6.y, 6.12.y, 6.18.y, and 6.19.y.
Affected products
- Linux Linux Kernel 3.8 to 6.6.130, 6.7 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10, 7.0-rc1 to 7.0-rc4
Timeline
- 2026-03-13: other: Patch authored
- 2026-04-03: disclosed: CVE published
- 2026-05-20: advisory: NVD analysis completed
References
- https://git.kernel.org/stable/c/2aa8a4fa8d5b7d0e1ebcec100e1a4d80a1f4b21a
- https://git.kernel.org/stable/c/403f94ddcb36c552fbef51dea735b131e3dcde8b
- https://git.kernel.org/stable/c/789204f980730258c983102c027c375238009c80
- https://git.kernel.org/stable/c/dce9dda0e3707e887977db44407989e9ead26611
- https://git.kernel.org/stable/c/f1c7701d3ac91b62d672c13690cf295821f0d5c3