usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
0Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()
When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length
against frame_max but does not verify that the datagram fits within the
declared block length. Additionally, when decoding multiple NTBs from a
single socket buffer, subsequent block lengths are not checked against the
actual remaining buffer data.
With these checks missing, a malicious USB host can specify datagram
offsets and lengths that point beyond the block, or supply secondary NTB
headers declaring lengths larger than the buffer. skb_put_data() then
copies adjacent kernel memory from skb_shared_info into the network skb.
Fix this by verifying that sufficient buffer space remains for the NTB
header before parsing, handling zero-length block declarations, ensuring
that block lengths never exceed the remaining buffer space, and verifying
that each datagram payload stays strictly within the block boundary.
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/1febec7e47cdcd01f43fb0211094e3010474666ehttps://git.kernel.org/stable/c/40c706a0224bde194667e3378c689b542fec4b44https://git.kernel.org/stable/c/41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5chttps://git.kernel.org/stable/c/e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381fhttps://git.kernel.org/stable/c/fff1059d139ef798bab917990524faaf25854ca8