CVE-2026-23447 | Linux Kernel up to 7.0-rc4 net cdc_ncm_rx_verify_ndp32 out-of-bounds (WID-SEC-2026-0985)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.129/6.12.77/6.18.19/6.19.9/7.0-rc4. Affected by this vulnerability is the function cdc_ncm_rx_verify_ndp32 of the component net. The manipulation results in out-of-bounds read.
This vulnerability is identified as CVE-2026-23447. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to upgrade the affected component.