CVE-2026-68368
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length against frame_max but does not verify that the datagram fits within the declared block length. Additionally, when decoding multiple NTBs from a single socket buffer, subsequent block lengths are not checked against the actual remaining buffer data.
With these checks missing, a malicious USB host can specify datagram offsets and lengths that point beyond the block, or supply secondary NTB headers declaring lengths larger than the buffer. skb_put_data() then copies adjacent kernel memory from skb_shared_info into the network skb.
Fix this by verifying that sufficient buffer space remains for the NTB header before parsing, handling zero-length block declarations, ensuring that block lengths never exceed the remaining buffer space, and verifying that each datagram payload stays strictly within the block boundary.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 < e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f | affected |
| Linux | Linux | 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 < fff1059d139ef798bab917990524faaf25854ca8 | affected |
| Linux | Linux | 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 < 40c706a0224bde194667e3378c689b542fec4b44 | affected |
| Linux | Linux | 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 < 41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c | affected |
| Linux | Linux | 2b74b0a04d3e9f9f08ff026e5663dce88ff94e52 < 1febec7e47cdcd01f43fb0211094e3010474666e | affected |
| Linux | Linux | f7e0611e207d8908c4f2858e244370529a76dbf7 | affected |
| Linux | Linux | b88ad6e714284b33a47834f5f2a294c2b37c66aa | affected |
| Linux | Linux | 471b23586387a32857778c511be60ab31c98dcfd | affected |
| Linux | Linux | 4f529c4d1e436230d3af7c09a3239677a14d2b46 | affected |
| Linux | Linux | ae6a5394d9fbe118bc95cfe376d6a9d91d7547e8 | affected |
| Linux | Linux | 5bdf93a2f5459f944b416b188178ca4a92fd206f | affected |
| Linux | Linux | ff3ba016263ee93a1c6209bf5ab1599de7ab1512 | affected |
| Linux | Linux | e7ca00f35d8a17af1ae19d529193ebc21bfda164 | affected |
| Linux | Linux | 4.9.235 < 4.10 | affected |
| Linux | Linux | 4.14.196 < 4.15 | affected |
| Linux | Linux | 4.19.143 < 4.20 | affected |
| Linux | Linux | 5.4.62 < 5.5 | affected |
| Linux | Linux | 5.8.6 < 5.9 | affected |
| Linux | Linux | 4.14.328 < 4.15 | affected |
| Linux | Linux | 4.19.297 < 4.20 | affected |
| Linux | Linux | 5.4.259 < 5.5 | affected |
| Linux | Linux | 5.9 | affected |
| Linux | Linux | 0 < 5.9 | unaffected |
| Linux | Linux | 6.6.148 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.101 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.42 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.6 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc5 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f
- https://git.kernel.org/stable/c/fff1059d139ef798bab917990524faaf25854ca8
- https://git.kernel.org/stable/c/40c706a0224bde194667e3378c689b542fec4b44
- https://git.kernel.org/stable/c/41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c
- https://git.kernel.org/stable/c/1febec7e47cdcd01f43fb0211094e3010474666e
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.