Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 4 weeks ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length against frame_max but does not verify that the datagram fits within the declared block length. Additionally, when decoding multiple NTBs from a single socket buffer, subsequent block lengths are not checked against the actual remaining buffer data. With these checks missing, a malicious USB host can specify datagram offsets and lengths that point beyond the block, or supply secondary NTB headers declaring lengths larger than the buffer. skb_put_data() then copies adjacent kernel memory from skb_shared_info into the network skb. Fix this by verifying that sufficient buffer space remains for the NTB header before parsing, handling zero-length block declarations, ensuring that block lengths never exceed the remaining buffer space, and verifying that each datagram payload stays strictly within the block boundary.

Affected products

Linux
  • <41fd5f2fb0027d3773ae949e3247c2e0a2a7fe5c
  • <4.20
  • =<6.6.*
  • <4.15
  • =<*
  • =<7.1.*
  • ==5.9
  • <40c706a0224bde194667e3378c689b542fec4b44
  • ==ff3ba016263ee93a1c6209bf5ab1599de7ab1512
  • ==4f529c4d1e436230d3af7c09a3239677a14d2b46
  • =<6.18.*
  • ==e7ca00f35d8a17af1ae19d529193ebc21bfda164
  • ==5bdf93a2f5459f944b416b188178ca4a92fd206f
  • <1febec7e47cdcd01f43fb0211094e3010474666e
  • <5.9
  • <e07751d0527ccc2a1c32eb0b0b7da3b4b9b5381f
  • ==b88ad6e714284b33a47834f5f2a294c2b37c66aa
  • <fff1059d139ef798bab917990524faaf25854ca8
  • =<6.12.*
  • ==ae6a5394d9fbe118bc95cfe376d6a9d91d7547e8
  • ==f7e0611e207d8908c4f2858e244370529a76dbf7
  • ==471b23586387a32857778c511be60ab31c98dcfd
  • <4.10
  • <5.5
  • <5.9