CVE-2026-68368: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() When unpacking host-supplied NTBs, ncm_unwrap_ntb() checks datagram length against frame_max but does not verify that the datagram fits within the declared block length. Additionally, when decoding multiple NTBs from a single socket buffer, subsequent block lengths are not checked against the actual remaining buffer data. With these checks missing, a malicious USB host can specify datagram offsets and lengths that point beyond the block, or supply secondary NTB headers declaring lengths larger than the buffer. skb_put_data() then copies adjacent kernel memory from skb_shared_info into the network skb. Fix this by verifying that sufficient buffer space remains for the NTB header before parsing, handling zero-length block declarations, ensuring that block lengths never exceed the remaining buffer space, and verifying that each datagram payload stays strictly within the block boundary.

Affected products

  • Linux Linux: from 4.9.235, before 4.10 (fixed in 4.10); from 4.14.196, before 4.15 (fixed in 4.15); from 4.19.143, before 4.20 (fixed in 4.20); from 5.4.62, before 5.5 (fixed in 5.5); from 5.8.6, before 5.9 (fixed in 5.9); from 4.14.328, before 4.15 (fixed in 4.15); …

Published 2026-08-10. Last modified 2026-08-19.