CVE-2026-31616
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/04/2026
Last modified:
28/04/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()<br />
<br />
A broken/bored/mean USB host can overflow the skb_shared_info->frags[]<br />
array on a Linux gadget exposing a Phonet function by sending an<br />
unbounded sequence of full-page OUT transfers.<br />
<br />
pn_rx_complete() finalizes the skb only when req->actual length,<br />
where req->length is set to PAGE_SIZE by the gadget. If the host always<br />
sends exactly PAGE_SIZE bytes per transfer, fp->rx.skb will never be<br />
reset and each completion will add another fragment via<br />
skb_add_rx_frag(). Once nr_frags exceeds MAX_SKB_FRAGS (default 17),<br />
subsequent frag stores overwrite memory adjacent to the shinfo on the<br />
heap.<br />
<br />
Drop the skb and account a length error when the frag limit is reached,<br />
matching the fix applied in t7xx by commit f0813bcd2d9d ("net: wwan:<br />
t7xx: fix potential skb->frags overflow in RX path").
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 2.6.32 (including) | 6.6.136 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.83 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 6.19.14 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 7.0 (including) | 7.0.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/4e476c25bfcab0535ba7c76a903ae77ca8747711
- https://git.kernel.org/stable/c/66f7471c4042e4eb300e30b5b9d87d1406862673
- https://git.kernel.org/stable/c/9ceff1251904901b0b4e5fe6350fcaffa368ce83
- https://git.kernel.org/stable/c/bd44ce09b9b569f49ed13e2d87d23d853fc7d6a7
- https://git.kernel.org/stable/c/c088d5dd2fffb4de1fb8e7f57751c8b82942180a
- https://git.kernel.org/stable/c/c9315ce9da3632c591666a29de82d3e92d46bec1



