{"id":"CVE-2026-31617","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()\n\nThe block_len read from the host-supplied NTB header is checked against\nntb_max but has no lower bou…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()\n\nThe block_len read from the host-supplied NTB header is checked against\nntb_max but has no lower bou…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-191"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 5.9, < 6.6.136","linux_kernel >= 6.12, < 6.12.83","linux_kernel >= 6.13, < 6.18.24","linux_kernel >= 6.19, < 6.19.14","linux_kernel >= 7.0, < 7.0.1"],"patched":["linux_kernel 7.0.1"],"published":"2026-04-24","updated":"2026-08-06","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-31617","references":[{"url":"https://git.kernel.org/stable/c/068a7f2749fff6462a0a908ec415b885fe430f50","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/0f156bb5334e588034ca68ac2ee92b23f66e56e7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1425655c2870054c3ab4712e2b6dbdd331597ada","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6762f8a95772265dd0c2ffe7f400493f3115b135","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/74908b0318d1df1188457040b8714ff4d4b68126","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8757a2593631443648218244b9788e193ae0fdc1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8b3b7bd3c02f98634baaf36c7fc7ac915f6517ca","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f993d30b95dc9557a8a96ceca11abed674c8acb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d58ba8f6546232f8414f396c189297dbee03f1a7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://access.redhat.com/security/cve/CVE-2026-31617","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2461448","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31617.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd"],"epss":0.00129,"epssPercentile":0.02879,"ingestedAt":"2026-08-06T13:59:36.973Z","slug":"CVE-2026-31617","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()\n\nThe block_len read from the host-supplied NTB header is checked against\nntb_max but has no lower bound. When block_len is smaller than\nopts->ndp_size, the bounds check of:\n\tndp_index > (block_len - opts->ndp_size)\nwill underflow producing a huge unsigned value that ndp_index can never\nexceed, defeating the check entirely.\n\nThe same underflow occurs in the datagram index checks against block_len\n- opts->dpe_size.  With those checks neutered, a malicious USB host can\nchoose ndp_index and datagram offsets that point past the actual\ntransfer, and the skb_put_data() copies adjacent kernel memory into the\nnetwork skb.\n\nFix this by rejecting block lengths that cannot hold at least the NTB\nheader plus one NDP.  This will make block_len - opts->ndp_size and\nblock_len - opts->dpe_size both well-defined.\n\nCommit 8d2b1a1ec9f5 (\"CDC-NCM: avoid overflow in sanity checking\") fixed\na related class of issues on the host side of NCM.\n\n## Affected\n\n- `linux_kernel >= 5.9, < 6.6.136`\n- `linux_kernel >= 6.12, < 6.12.83`\n- `linux_kernel >= 6.13, < 6.18.24`\n- `linux_kernel >= 6.19, < 6.19.14`\n- `linux_kernel >= 7.0, < 7.0.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.1`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}