Answer in brief
CVE-2026-23447 records a Unknown severity vulnerability in net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0fa81b304a7973a499f844176ca031109487dd31 <baf246d6680befde2086b1df9eb3aaba3fb6853f || >=0fa81b304a7973a499f844176ca031109487dd31 <125f932a76a97904ef8a555f1dd53e5d0e288c54 || >=0fa81b304a7973a499f844176ca031109487dd31 <af0d1613d6751489dbf9f69aac1123f0b1e566e5 || >=0fa81b304a7973a499f844176ca031109487dd31 <a5bd5a2710310c965ea4153cba4210988a3454e2 || >=0fa81b304a7973a499f844176ca031109487dd31 <de70da1fb1d152e981ecb3157f7ec2b633005c16 || >=0fa81b304a7973a499f844176ca031109487dd31 <77914255155e68a20aa41175edeecf8121dac391 || 8cf7db86a8984ffa3a3388a8df12bc0aa4c79bd7 || 4ca8b8855264cf1439cdab3da7049bd1e3c2a9e6 || a270ca35a9499b58366d696d3290eaa4697a42db || >=4.14.317 <4.15 || >=4.19.285 <4.20 || >=5.4.245 <5.5 | baf246d6680befde2086b1df9eb3aaba3fb6853f, 125f932a76a97904ef8a555f1dd53e5d0e288c54, af0d1613d6751489dbf9f69aac1123f0b1e566e5, a5bd5a2710310c965ea4153cba4210988a3454e2, de70da1fb1d152e981ecb3157f7ec2b633005c16, 77914255155e68a20aa41175edeecf8121dac391, 4.15, 4.20, 5.5 |
| Linux/Linuxgeneric | 5.7 | Not reported |
Published upstream
Apr 3, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 14, 2026
In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against the total skb length without accounting for ndpoffset, allowing out-of-bounds reads when the NDP32 is placed near the end of the NTB. Add ndpoffset to the nframes bounds check and use struct_size_t() to express the NDP-plus-DPE-array size more clearly. Compile-tested only.
Quoted source text, attributed separately from HOL analysis.