Executive brief
The Linux kernel USB Network Control Model (NCM) gadget function contains an integer overflow vulnerability in the ndp_index variable. A malicious USB host can supply a specially crafted offset that causes the signed integer to overflow and become negative, bypassing boundary checks and leading to out-of-bounds memory reads. This could result in information disclosure or system instability on devices using NCM USB gadget functionality.
Technical details
The vulnerability is a signed integer overflow in the f_ncm.c USB gadget driver. The variable ndp_index is declared as a signed int but stores the unsigned return value of get_ncm(). An attacker can supply a large offset that overflows the signed ndp_index, making it negative. Because subsequent boundary comparisons treat ndp_index as unsigned, the negative value bypasses sanity checks, leading to an out-of-bounds read when calculating the NDP block address (ntb_ptr + ndp_index). The fix changes ndp_index to unsigned int to ensure consistent unsigned comparisons. This is a low-severity issue affecting the USB gadget subsystem, reachable only by a malicious USB host with a direct connection to the device.
Affected products
- Linux Linux kernel multiple versions prior to fix (affects NCM gadget driver)
Timeline
- 2026-07-20: other: Patch authored by Sonali Pradhan
- 2026-08-19: patched: Patch committed to stable kernel trees
- 2026-08-22: disclosed: CVE published