๐Ÿ” CVE Alert

CVE-2026-74679

UNKNOWN 0.0

usb: gadget: f_ncm: Use unsigned int for ndp_index

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: Use unsigned int for ndp_index The variable ndp_index is declared as a signed integer, but it stores the return value of get_ncm(), which is unsigned. A malicious host can supply a large offset that overflows the signed ndp_index, making it negative. Because ndp_index is compared against unsigned bounds, this negative value bypasses sanity checks and leads to an out-of-bounds read when calculating the address of the NDP block (ntb_ptr + ndp_index). Fix this by changing ndp_index to unsigned int to ensure consistent unsigned comparisons throughout the function.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
370af734dfaf8336b496b386e194648e097e248a < 9c8c6825a750fcd3efbe922847ca70ccd5a66857 370af734dfaf8336b496b386e194648e097e248a < a1c0deeba4a46481543d6b09c665f758c54c3a1a 370af734dfaf8336b496b386e194648e097e248a < d13f650a3485b58c124b3cda45597e8002c9c833 370af734dfaf8336b496b386e194648e097e248a < 11413d7ed42174b8f5d8d0b6a25d10dc88239b21 370af734dfaf8336b496b386e194648e097e248a < 5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3 370af734dfaf8336b496b386e194648e097e248a < d328fdc607fa1bb668ad512e1c918a120f78f337 370af734dfaf8336b496b386e194648e097e248a < fc9e54e22845c4da29588ca0986cb7c795b5a262 370af734dfaf8336b496b386e194648e097e248a < 6b1c8a9403a26cb0fed7a648916c74dc236da591
Linux / Linux
3.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9c8c6825a750fcd3efbe922847ca70ccd5a66857 git.kernel.org: https://git.kernel.org/stable/c/a1c0deeba4a46481543d6b09c665f758c54c3a1a git.kernel.org: https://git.kernel.org/stable/c/d13f650a3485b58c124b3cda45597e8002c9c833 git.kernel.org: https://git.kernel.org/stable/c/11413d7ed42174b8f5d8d0b6a25d10dc88239b21 git.kernel.org: https://git.kernel.org/stable/c/5b2b3a3229a3f4c493ffdee53aee2f173b6f13b3 git.kernel.org: https://git.kernel.org/stable/c/d328fdc607fa1bb668ad512e1c918a120f78f337 git.kernel.org: https://git.kernel.org/stable/c/fc9e54e22845c4da29588ca0986cb7c795b5a262 git.kernel.org: https://git.kernel.org/stable/c/6b1c8a9403a26cb0fed7a648916c74dc236da591