{"id":"CVE-2026-98237","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain\n\nThe NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is\nzero","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain\n\nThe NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is\nzero.  Nothing requires the offsets to a…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 3ed36ee1b29b028f6bc2ebe100152f61a33df05a","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < e4b2c7b50d4f4aa1ddfff731b136d65f65b2b526","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 19b5e8dd884a530d04482e1a8e547f43cad17ed7","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 24ade82d6d993274e99c2c6998848751c35292e7","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 8dad70ff7e25cbcfbcb5101fdbf36d98003eb653","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 829fec45122da58d77a55a3b7ca514dafab98e77","Linux >= aa730a9905b7b079ef2fffdab7f15dbb842f5c7c < 5d063822ac5184939c1ed377a339a01d8ae814e8","Linux 5.15"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:11.500","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98237","references":[{"url":"https://git.kernel.org/stable/c/19b5e8dd884a530d04482e1a8e547f43cad17ed7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/24ade82d6d993274e99c2c6998848751c35292e7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3ed36ee1b29b028f6bc2ebe100152f61a33df05a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5d063822ac5184939c1ed377a339a01d8ae814e8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/829fec45122da58d77a55a3b7ca514dafab98e77","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8dad70ff7e25cbcfbcb5101fdbf36d98003eb653","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e4b2c7b50d4f4aa1ddfff731b136d65f65b2b526","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.434Z","slug":"CVE-2026-98237","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain\n\nThe NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is\nzero.  Nothing requires the offsets to advance, so a modem that\npoints an NDP at itself, or at an earlier NDP, keeps the loop\nspinning forever on one CPU.\n\nBreak out when the next NDP offset is not larger than the current\none.\n\n\nVerified in a QEMU guest with a fault injector feeding the driver's\nreceive callback an NTB whose single NDP points at itself: the\nunpatched driver spins in mhi_mbim_rx() with one CPU pinned at 100%\nand the thread never returns.  With this check the loop terminates\nwithin one iteration.\n\nChanges in v2: move the non-increasing check to the wNextNdpIndex\nretrieval site, as suggested by Loic Poulain, instead of tracking\nthe previous offset in a separate variable.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}