PT-2026-30142 · Linux · Linux Kernel

Published

2026-04-03

·

Updated

2026-05-03

·

CVE-2026-23447

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A bounds-check issue exists in the cdc ncm rx verify ndp32() function within the Linux kernel's networking subsystem for USB Network (cdc ncm). The issue arises from a failure to account for ndpoffset when validating the DPE array size against the total skb length, potentially leading to out-of-bounds reads when the NDP32 is positioned near the end of the NTB. The fix involves adding ndpoffset to the nframes bounds check and using struct size t() to clarify the NDP-plus-DPE-array size.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2026-23447
ECHO-B1E1-3445-E2BF
OESA-2026-2172
OESA-2026-2173
OESA-2026-2176

Affected Products

Linux Kernel