<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 23:27:26 +0000</lastBuildDate>
    <item>
      <title>CVE-2023-52894 — usb: gadget: f_ncm: fix potential NULL ptr deref in ncm_bitrate()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2023-52894</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: f_ncm: fix potential NULL ptr deref in ncm_bitrate()&lt;/p&gt;
&lt;p&gt;In Google internal bug 265639009 we&amp;#39;ve received an (as yet) unreproducible
crash report from an aarch64 GKI 5.10.149-android13 running device.&lt;/p&gt;
&lt;p&gt;AFAICT the source code is at:
  https://android.googlesource.com/kernel/common/+/refs/tags/ASB-2022-12-05_13-5.10&lt;/p&gt;
&lt;p&gt;The call stack is:
  ncm_close() -&amp;gt; ncm_notify() -&amp;gt; ncm_do_notify()
with the crash at:
  ncm_do_notify+0x98/0x270
Code: 79000d0b b9000a6c f940012a f9400269 (b9405d4b)&lt;/p&gt;
&lt;p&gt;Which I believe disassembles to (I don&amp;#39;t know ARM assembly, but it looks sane enough to me...):&lt;/p&gt;
&lt;p&gt;// halfword (16-bit) store presumably to event-&amp;gt;wLength (at offset 6 of struct usb_cdc_notification)
  0B 0D 00 79    strh w11, [x8, #6]&lt;/p&gt;
&lt;p&gt;// word (32-bit) store presumably to req-&amp;gt;Length (at offset 8 of struct usb_request)
  6C 0A 00 B9    str  w12, [x19, #8]&lt;/p&gt;
&lt;p&gt;// x10 (NULL) was read here from offset 0 of valid pointer x9
  // IMHO we&amp;#39;re reading &amp;#39;cdev-&amp;gt;gadget&amp;#39; and getting NULL
  // gadget is indeed at offset 0 of struct usb_composite_dev
  2A 01 40 F9    ldr  x10, [x9]&lt;/p&gt;
&lt;p&gt;// loading req-&amp;gt;buf pointer, which is at offset 0 of struct usb_request
  69 02 40 F9    ldr  x9, [x19]&lt;/p&gt;
&lt;p&gt;// x10 is null, crash, appears to be attempt to read cdev-&amp;gt;gadget-&amp;gt;max_speed
  4B 5D 40 B9    ldr  w11, [x10, #0x5c]&lt;/p&gt;
&lt;p&gt;which seems to line up with ncm_do_notify() case NCM_NOTIFY_SPEED code fragment:&lt;/p&gt;
&lt;p&gt;event-&amp;gt;wLength = cpu_to_le16(8);
  req-&amp;gt;length =…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;usb: gadget: f_ncm: fix potential NULL ptr deref in ncm_bitrate()&lt;/p&gt;
&lt;p&gt;In Google internal bug 265639009 we&amp;#39;ve received an (as yet) unreproducible
crash report from an aarch64 GKI 5.10.149-android13 running device.&lt;/p&gt;
&lt;p&gt;AFAICT the source code is at:
  https://android.googlesource.com/kernel/common/+/refs/tags/ASB-2022-12-05_13-5.10&lt;/p&gt;
&lt;p&gt;The call stack is:
  ncm_close() -&amp;gt; ncm_notify() -&amp;gt; ncm_do_notify()
with the crash at:
  ncm_do_notify+0x98/0x270
Code: 79000d0b b9000a6c f940012a f9400269 (b9405d4b)&lt;/p&gt;
&lt;p&gt;Which I believe disassembles to (I don&amp;#39;t know ARM assembly, but it looks sane enough to me...):&lt;/p&gt;
&lt;p&gt;// halfword (16-bit) store presumably to event-&amp;gt;wLength (at offset 6 of struct usb_cdc_notification)
  0B 0D 00 79    strh w11, [x8, #6]&lt;/p&gt;
&lt;p&gt;// word (32-bit) store presumably to req-&amp;gt;Length (at offset 8 of struct usb_request)
  6C 0A 00 B9    str  w12, [x19, #8]&lt;/p&gt;
&lt;p&gt;// x10 (NULL) was read here from offset 0 of valid pointer x9
  // IMHO we&amp;#39;re reading &amp;#39;cdev-&amp;gt;gadget&amp;#39; and getting NULL
  // gadget is indeed at offset 0 of struct usb_composite_dev
  2A 01 40 F9    ldr  x10, [x9]&lt;/p&gt;
&lt;p&gt;// loading req-&amp;gt;buf pointer, which is at offset 0 of struct usb_request
  69 02 40 F9    ldr  x9, [x19]&lt;/p&gt;
&lt;p&gt;// x10 is null, crash, appears to be attempt to read cdev-&amp;gt;gadget-&amp;gt;max_speed
  4B 5D 40 B9    ldr  w11, [x10, #0x5c]&lt;/p&gt;
&lt;p&gt;which seems to line up with ncm_do_notify() case NCM_NOTIFY_SPEED code fragment:&lt;/p&gt;
&lt;p&gt;event-&amp;gt;wLength = cpu_to_le16(8);
  req-&amp;gt;length =…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2023-52894</guid>
    </item>
  </channel>
</rss>
