usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length
against frame_max but does not verify that the datagram fits within the
declared block length. Additionally, when decoding multiple NTBs from a
single socket buffer, subsequent block lengths are not checked against the
actual remaining buffer data.
With these checks missing, a malicious USB host can specify datagram
offsets and lengths that point beyond the block, or supply secondary NTB
headers declaring lengths larger than the buffer. skb_put_data() then
copies adjacent kernel memory from skb_shared_info into the network skb.
Fix this by verifying that sufficient buffer space remains for the NTB
header before parsing, handling zero-length block declarations, ensuring
that block lengths never exceed the remaining buffer space, and verifying
that each datagram payload stays strictly within the block boundary.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/1febec7e47cdcd01f43fb0211094e3010474666ehttps://git.kernel.org/stable/c/35d15bbaec0557330e774ec31412ef508de6e0e0https://git.kernel.org/stable/c/40c706a0224bde194667e3378c689b542fec4b44https://git.kernel.org/stable/c/41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5chttps://git.kernel.org/stable/c/6b2be489eaa6293e60549005d91f15ceb150510fhttps://git.kernel.org/stable/c/e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381fhttps://git.kernel.org/stable/c/f87ed889f0f7417b8938c98d8833f559b755373chttps://git.kernel.org/stable/c/fff1059d139ef798bab917990524faaf25854ca8