---
id: CVE-2026-23447
title: 'net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check

  The same bounds-check bug fixed for NDP16 in the previous patch also
  exists in cdc_ncm_rx_verify_ndp32()…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 0fa81b304a7973a499f844176ca031109487dd31 <
    baf246d6680befde2086b1df9eb3aaba3fb6853f
  - >-
    Linux >= 0fa81b304a7973a499f844176ca031109487dd31 <
    125f932a76a97904ef8a555f1dd53e5d0e288c54
  - >-
    Linux >= 0fa81b304a7973a499f844176ca031109487dd31 <
    af0d1613d6751489dbf9f69aac1123f0b1e566e5
  - >-
    Linux >= 0fa81b304a7973a499f844176ca031109487dd31 <
    a5bd5a2710310c965ea4153cba4210988a3454e2
  - >-
    Linux >= 0fa81b304a7973a499f844176ca031109487dd31 <
    de70da1fb1d152e981ecb3157f7ec2b633005c16
  - >-
    Linux >= 0fa81b304a7973a499f844176ca031109487dd31 <
    77914255155e68a20aa41175edeecf8121dac391
  - Linux 8cf7db86a8984ffa3a3388a8df12bc0aa4c79bd7
  - Linux 4ca8b8855264cf1439cdab3da7049bd1e3c2a9e6
  - Linux a270ca35a9499b58366d696d3290eaa4697a42db
  - Linux >= 4.14.317 < 4.15
  - Linux >= 4.19.285 < 4.20
  - Linux >= 5.4.245 < 5.5
  - Linux 5.7
published: '2026-04-03'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T11:58:13.940Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-23447'
references:
  - url: 'https://git.kernel.org/stable/c/baf246d6680befde2086b1df9eb3aaba3fb6853f'
  - url: 'https://git.kernel.org/stable/c/125f932a76a97904ef8a555f1dd53e5d0e288c54'
  - url: 'https://git.kernel.org/stable/c/af0d1613d6751489dbf9f69aac1123f0b1e566e5'
  - url: 'https://git.kernel.org/stable/c/a5bd5a2710310c965ea4153cba4210988a3454e2'
  - url: 'https://git.kernel.org/stable/c/de70da1fb1d152e981ecb3157f7ec2b633005c16'
  - url: 'https://git.kernel.org/stable/c/77914255155e68a20aa41175edeecf8121dac391'
tags:
  - cve.org
epss: 0.00129
epssPercentile: 0.02938
ingestedAt: '2026-09-14T15:23:07.459Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check

The same bounds-check bug fixed for NDP16 in the previous patch also
exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated
against the total skb length without accounting for ndpoffset, allowing
out-of-bounds reads when the NDP32 is placed near the end of the NTB.

Add ndpoffset to the nframes bounds check and use struct_size_t() to
express the NDP-plus-DPE-array size more clearly.

Compile-tested only.

## Affected

- `Linux >= 0fa81b304a7973a499f844176ca031109487dd31 < baf246d6680befde2086b1df9eb3aaba3fb6853f`
- `Linux >= 0fa81b304a7973a499f844176ca031109487dd31 < 125f932a76a97904ef8a555f1dd53e5d0e288c54`
- `Linux >= 0fa81b304a7973a499f844176ca031109487dd31 < af0d1613d6751489dbf9f69aac1123f0b1e566e5`
- `Linux >= 0fa81b304a7973a499f844176ca031109487dd31 < a5bd5a2710310c965ea4153cba4210988a3454e2`
- `Linux >= 0fa81b304a7973a499f844176ca031109487dd31 < de70da1fb1d152e981ecb3157f7ec2b633005c16`
- `Linux >= 0fa81b304a7973a499f844176ca031109487dd31 < 77914255155e68a20aa41175edeecf8121dac391`
- `Linux 8cf7db86a8984ffa3a3388a8df12bc0aa4c79bd7`
- `Linux 4ca8b8855264cf1439cdab3da7049bd1e3c2a9e6`
- `Linux a270ca35a9499b58366d696d3290eaa4697a42db`
- `Linux >= 4.14.317 < 4.15`
- `Linux >= 4.19.285 < 4.20`
- `Linux >= 5.4.245 < 5.5`
- `Linux 5.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
