# CVE-2026-23447

## Summary

- **CVE ID:** CVE-2026-23447
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Apr 3, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check

The same bounds-check bug fixed for NDP16 in the previous patch also
exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated
against the total skb length without accounting for ndpoffset, allowing
out-of-bounds reads when the NDP32 is placed near the end of the NTB.

Add ndpoffset to the nframes bounds check and use struct_size_t() to
express the NDP-plus-DPE-array size more clearly.

Compile-tested only.

## Affected Products

- Linux — Linux (0fa81b304a7973a499f844176ca031109487dd31)
- Linux — Linux (8cf7db86a8984ffa3a3388a8df12bc0aa4c79bd7)
- Linux — Linux (4ca8b8855264cf1439cdab3da7049bd1e3c2a9e6)
- Linux — Linux (a270ca35a9499b58366d696d3290eaa4697a42db)
- Linux — Linux (5.7)
- Linux — Linux (0)
- Linux — Linux (6.6.130)
- Linux — Linux (6.12.78)
- Linux — Linux (6.18.20)
- Linux — Linux (6.19.10)
- Linux — Linux (7.0-rc5)
- Linux — Linux (7.0)
- Linux — Linux (4.14.317)
- Linux — Linux (4.19.285)
- Linux — Linux (5.4.245)
- Linux — Linux (6.1.188)

## References

- [CNA](https://git.kernel.org/stable/c/125f932a76a97904ef8a555f1dd53e5d0e288c54)
- [CNA](https://git.kernel.org/stable/c/af0d1613d6751489dbf9f69aac1123f0b1e566e5)
- [CNA](https://git.kernel.org/stable/c/a5bd5a2710310c965ea4153cba4210988a3454e2)
- [CNA](https://git.kernel.org/stable/c/de70da1fb1d152e981ecb3157f7ec2b633005c16)
- [CNA](https://git.kernel.org/stable/c/77914255155e68a20aa41175edeecf8121dac391)
- [CNA](https://git.kernel.org/stable/c/baf246d6680befde2086b1df9eb3aaba3fb6853f)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._