CVE-2026-23320NULL Pointer Dereference in Kernel

Severity
5.5MEDIUM
No vector
EPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 10
Latest updateMar 25

Description

usb: gadget: f_ncm: align net_device lifecycle with bind/unbind Mariner: Mariner Linux: Linux Customer Action Required: Yes

Affected Packages2 packages

Linuxlinux/linux_kernel3.11.06.18.17+1
Debianlinux/linux_kernel< 6.19.8-1

🔴Vulnerability Details

3
OSV
CVE-2026-23320: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: align net_device lifecycle with bind/unbind Currently, the net2026-03-25
GHSA
GHSA-8459-cmh7-px33: In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: align net_device lifecycle with bind/unbind Currently, the n2026-03-25
OSV
usb: gadget: f_ncm: align net_device lifecycle with bind/unbind2026-03-25

📋Vendor Advisories

2
Red Hat
kernel: usb: gadget: f_ncm: align net_device lifecycle with bind/unbind2026-03-25
Microsoft
usb: gadget: f_ncm: align net_device lifecycle with bind/unbind2026-03-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-23320 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-23320 kernel: usb: gadget: f_ncm: align net_device lifecycle with bind/unbind2026-03-25
CVE-2026-23320 — NULL Pointer Dereference in Kernel | cvebase