CVE-2026-31623

Source
https://cve.org/CVERecord?id=CVE-2026-31623
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31623.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-31623
Downstream
Related
Published
2026-04-24T14:42:40.566Z
Modified
2026-06-18T03:57:40.207098463Z
Summary
net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()
Details

In the Linux kernel, the following vulnerability has been resolved:

net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()

A malicious USB device claiming to be a CDC Phonet modem can overflow the skbsharedinfo->frags[] array by sending an unbounded sequence of full-page bulk transfers.

Drop the skb and increment the length error when the frag limit is reached. This matches the same fix that commit f0813bcd2d9d ("net: wwan: t7xx: fix potential skb->frags overflow in RX path") did for the t7xx driver.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31623.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
87cf65601e1709e57f7e28f0f7b3eb0a992c1782
Fixed
6807ff49bf796b3823b1e29f97b69316a40a9a94
Fixed
0c5c65a17db729fc63ab656bdaaf0e675a9dbeac
Fixed
6053620fdbcd89fa7e755644efdaab78e0daaae7
Fixed
d4e1946bea8d6441835eb3fd09b19237ba366a6f
Fixed
a23b1b1aaf41e174181d5853a70e65d4d01e648c
Fixed
c183d5775129a0a7495bd61a6e57ec230dcf01e5
Fixed
ebf75c6301c4972a87542ebf2d994c6391eb5d46
Fixed
9989938d13cc5ba8447eeed5a61acfcf61bc6801
Fixed
600dc40554dc5ad1e6f3af51f700228033f43ea7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31623.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.31
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.136
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.83
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.24
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.14
Type
ECOSYSTEM
Events
Introduced
6.20.0
Fixed
7.0.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-31623.json"