Answer in brief
CVE-2026-74679 records a Unknown severity vulnerability in usb: gadget: f_ncm: Use unsigned int for ndp_index. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=370af734dfaf8336b496b386e194648e097e248a <9c8c6825a750fcd3efbe922847ca70ccd5a66857 || >=370af734dfaf8336b496b386e194648e097e248a <a1c0deeba4a46481543d6b09c665f758c54c3a1a || >=370af734dfaf8336b496b386e194648e097e248a <d13f650a3485b58c124b3cda45597e8002c9c833 || >=370af734dfaf8336b496b386e194648e097e248a <11413d7ed42174b8f5d8d0b6a25d10dc88239b21 || >=370af734dfaf8336b496b386e194648e097e248a <5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3 || >=370af734dfaf8336b496b386e194648e097e248a <d328fdc607fa1bb668ad512e1c918a120f78f337 || >=370af734dfaf8336b496b386e194648e097e248a <fc9e54e22845c4da29588ca0986cb7c795b5a262 || >=370af734dfaf8336b496b386e194648e097e248a <6b1c8a9403a26cb0fed7a648916c74dc236da591 | 9c8c6825a750fcd3efbe922847ca70ccd5a66857, a1c0deeba4a46481543d6b09c665f758c54c3a1a, d13f650a3485b58c124b3cda45597e8002c9c833, 11413d7ed42174b8f5d8d0b6a25d10dc88239b21, 5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3, d328fdc607fa1bb668ad512e1c918a120f78f337, fc9e54e22845c4da29588ca0986cb7c795b5a262, 6b1c8a9403a26cb0fed7a648916c74dc236da591 |
| Linux/Linuxgeneric | 3.17 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Use unsigned int for ndp_index The variable ndp_index is declared as a signed integer, but it stores the return value of get_ncm(), which is unsigned. A malicious host can supply a large offset that overflows the signed ndp_index, making it negative. Because ndp_index is compared against unsigned bounds, this negative value bypasses sanity checks and leads to an out-of-bounds read when calculating the address of the NDP block (ntb_ptr + ndp_index). Fix this by changing ndp_index to unsigned int to ensure consistent unsigned comparisons throughout the function.
Quoted source text, attributed separately from HOL analysis.