cbcvebase.
CVE-2026-23447
published 2026-04-03

CVE-2026-23447: In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against the total skb length without accounting for ndpoffset, allowing out-of-bounds reads when the NDP32 is placed near the end of the NTB. Add ndpoffset to the nframes bounds check and use struct_size_t() to express the NDP-plus-DPE-array size more clearly. Compile-tested only.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0fa81b304a7973a499f844176ca031109487dd31 < 125f932a76a97904ef8a555f1dd53e5d0e288c54125f932a76a97904ef8a555f1dd53e5d0e288c54
linuxlinux>= 0fa81b304a7973a499f844176ca031109487dd31 < af0d1613d6751489dbf9f69aac1123f0b1e566e5af0d1613d6751489dbf9f69aac1123f0b1e566e5
linuxlinux>= 0fa81b304a7973a499f844176ca031109487dd31 < a5bd5a2710310c965ea4153cba4210988a3454e2a5bd5a2710310c965ea4153cba4210988a3454e2
linuxlinux>= 0fa81b304a7973a499f844176ca031109487dd31 < de70da1fb1d152e981ecb3157f7ec2b633005c16de70da1fb1d152e981ecb3157f7ec2b633005c16
linuxlinux>= 0fa81b304a7973a499f844176ca031109487dd31 < 77914255155e68a20aa41175edeecf8121dac39177914255155e68a20aa41175edeecf8121dac391
linuxlinux>= 4.14.317 < 4.154.15
linuxlinux>= 4.19.285 < 4.204.20
linuxlinux>= 5.4.245 < 5.55.5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 4.14.317 < 4.154.15
linuxlinux_kernel>= 4.19.285 < 4.204.20
linuxlinux_kernel>= 5.4.245 < 5.55.5
linuxlinux_kernel>= 5.7.1 < 6.6.1306.6.130
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-gcp

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat6.6MEDIUM
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.