CVE-2026-31617

EUVD-2026-25510
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()

The block_len read from the host-supplied NTB header is checked against
ntb_max but has no lower bound. When block_len is smaller than
opts->ndp_size, the bounds check of:
	ndp_index > (block_len - opts->ndp_size)
will underflow producing a huge unsigned value that ndp_index can never
exceed, defeating the check entirely.

The same underflow occurs in the datagram index checks against block_len
- opts->dpe_size.  With those checks neutered, a malicious USB host can
choose ndp_index and datagram offsets that point past the actual
transfer, and the skb_put_data() copies adjacent kernel memory into the
network skb.

Fix this by rejecting block lengths that cannot hold at least the NTB
header plus one NDP.  This will make block_len - opts->ndp_size and
block_len - opts->dpe_size both well-defined.

Commit 8d2b1a1ec9f5 ("CDC-NCM: avoid overflow in sanity checking") fixed
a related class of issues on the host side of NCM.
Wrap or Wraparound
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
5.9 ≤
𝑥
< 6.6.136
linuxlinux_kernel
6.12 ≤
𝑥
< 6.12.83
linuxlinux_kernel
6.13 ≤
𝑥
< 6.18.24
linuxlinux_kernel
6.19 ≤
𝑥
< 6.19.14
linuxlinux_kernel
7.0 ≤
𝑥
< 7.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.176-1
fixed
bookworm (security)
6.1.177-1
fixed
bullseye
vulnerable
bullseye (security)
5.10.259-1
fixed
forky
7.1.3-1
fixed
sid
7.1.4-1
fixed
trixie
6.12.94-1
fixed
trixie (security)
6.12.96-1
fixed
linux-6.1
bullseye (security)
6.1.176-1~deb11u1
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kernel-64kb
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-default
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-default-base
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2.150700.17.41.4
fixed
kernel-obs-build
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed
kernel-source
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.1
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.1
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.1
fixed
kernel-zfcpdump
suse enterprise desktop 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise sap 15 SP7
6.4.0-150700.53.73.2
fixed
suse enterprise server 15 SP7
6.4.0-150700.53.73.2
fixed