CVE-2026-23448
In the Linux kernel, the following vulnerability has been resolved:
net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check
cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE entries fit within the skb. The first check correctly accounts for ndpoffset:
but the second check omits it:
This validates the DPE array size against the total skb length as if the NDP were at offset 0, rather than at ndpoffset. When the NDP is placed near the end of the NTB (large wNdpIndex), the DPE entries can extend past the skb data buffer even though the check passes. cdc_ncm_rx_fixup() then reads out-of-bounds memory when iterating the DPE array.
Leer descripción completaMostrar menos
Add ndpoffset to the nframes bounds check and use struct_size_t() to express the NDP-plus-DPE-array size more clearly.
Detalles técnicos trazas, registros y código del informe original
if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in->len)
if ((sizeof(struct usb_cdc_ncm_ndp16) +
ret * (sizeof(struct usb_cdc_ncm_dpe16))) > skb_in->len)CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1005Data from Local Systemcollection80 % - Impacto secundario
T1499.004Application or System Exploitationimpact75 %
AV:L, PR:L, UI:N indica escalada local sin interacción (T1068). El desbordamiento de búfer permite leer memoria fuera de límites (T1005) y causar DoS por corrupción de datos del kernel (T1499.004).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-129
Referencias
- https://git.kernel.org/stable/c/2aa8a4fa8d5b7d0e1ebcec100e1a4d80a1f4b21a
- https://git.kernel.org/stable/c/403f94ddcb36c552fbef51dea735b131e3dcde8b
- https://git.kernel.org/stable/c/63c35b8fce77a7892e8fa06c540d4943145506eb
- https://git.kernel.org/stable/c/789204f980730258c983102c027c375238009c80
- https://git.kernel.org/stable/c/dce9dda0e3707e887977db44407989e9ead26611
- https://git.kernel.org/stable/c/f1c7701d3ac91b62d672c13690cf295821f0d5c3
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23448",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ff06ab13a4ccae4acb44a2d4e3ece367b616ab50",
"lessThan": "63c35b8fce77a7892e8fa06c540d4943145506eb",
"versionType": "git"
},
{
"status": "affected",
"version": "ff06ab13a4ccae4acb44a2d4e3ece367b616ab50",
"lessThan": "f1c7701d3ac91b62d672c13690cf295821f0d5c3",
"versionType": "git"
},
{
"status": "affected",
"version": "ff06ab13a4ccae4acb44a2d4e3ece367b616ab50",
"lessThan": "789204f980730258c983102c027c375238009c80",
"versionType": "git"
},
{
"status": "affected",
"version": "ff06ab13a4ccae4acb44a2d4e3ece367b616ab50",
"lessThan": "403f94ddcb36c552fbef51dea735b131e3dcde8b",
"versionType": "git"
},
{
"status": "affected",
"version": "ff06ab13a4ccae4acb44a2d4e3ece367b616ab50",
"lessThan": "dce9dda0e3707e887977db44407989e9ead26611",
"versionType": "git"
},
{
"status": "affected",
"version": "ff06ab13a4ccae4acb44a2d4e3ece367b616ab50",
"lessThan": "2aa8a4fa8d5b7d0e1ebcec100e1a4d80a1f4b21a",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/usb/cdc_ncm.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.20",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.10",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/usb/cdc_ncm.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-04-03T16:16:30.863",
"references": [
{
"url": "https://git.kernel.org/stable/c/2aa8a4fa8d5b7d0e1ebcec100e1a4d80a1f4b21a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/403f94ddcb36c552fbef51dea735b131e3dcde8b",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/63c35b8fce77a7892e8fa06c540d4943145506eb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/789204f980730258c983102c027c375238009c80",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/dce9dda0e3707e887977db44407989e9ead26611",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f1c7701d3ac91b62d672c13690cf295821f0d5c3",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-129"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check\n\ncdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE\nentries fit within the skb. The first check correctly accounts for\nndpoffset:\n\n if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in->len)\n\nbut the second check omits it:\n\n if ((sizeof(struct usb_cdc_ncm_ndp16) +\n ret * (sizeof(struct usb_cdc_ncm_dpe16))) > skb_in->len)\n\nThis validates the DPE array size against the total skb length as if\nthe NDP were at offset 0, rather than at ndpoffset. When the NDP is\nplaced near the end of the NTB (large wNdpIndex), the DPE entries can\nextend past the skb data buffer even though the check passes.\ncdc_ncm_rx_fixup() then reads out-of-bounds memory when iterating\nthe DPE array.\n\nAdd ndpoffset to the nframes bounds check and use struct_size_t() to\nexpress the NDP-plus-DPE-array size more clearly."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nnet: usb: cdc_ncm: añadir ndpoffset a la comprobación de límites de nframes de NDP16\n\ncdc_ncm_rx_verify_ndp16() valida que la cabecera NDP y sus entradas DPE encajan dentro del skb. La primera comprobación tiene en cuenta correctamente ndpoffset:\n\nif ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in -> len)\n\npero la segunda comprobación lo omite:\n\nif ((sizeof(struct usb_cdc_ncm_ndp16) + ret * (sizeof(struct usb_cdc_ncm_dpe16))) > skb_in -> len)\n\nEsto valida el tamaño del array DPE contra la longitud total del skb como si el NDP estuviera en el offset 0, en lugar de en ndpoffset. Cuando el NDP se coloca cerca del final del NTB (wNdpIndex grande), las entradas DPE pueden extenderse más allá del búfer de datos del skb aunque la comprobación pase. cdc_ncm_rx_fixup() entonces lee memoria fuera de límites al iterar el array DPE.\n\nAñadir ndpoffset a la comprobación de límites de nframes y usar struct_size_t() para expresar el tamaño del array NDP-más-DPE más claramente."
}
],
"lastModified": "2026-09-14T12:17:40.310",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EFE88BB9-3F34-4285-87EF-4D5EF076BBB0",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "3.8"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28D591F5-B196-4CC9-905C-DC80F116E7A8",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E5571059-6552-48E7-9BEF-3E358C387171",
"versionEndExcluding": "6.18.20",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96D34333-38BE-4414-9E79-6EB764329581",
"versionEndExcluding": "6.19.10",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F253B622-8837-4245-BCE5-A7BF8FC76A16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AE85AD8-4641-4E7C-A2F4-305E2CD9EE64"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F666C8D8-6538-46D4-B318-87610DE64C34"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02259FDA-961B-47BC-AE7F-93D7EC6E90C2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}