Description
In the Linux kernel, the following vulnerability has been resolved:

net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain

The NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is
zero. Nothing requires the offsets to advance, so a modem that
points an NDP at itself, or at an earlier NDP, keeps the loop
spinning forever on one CPU.

Break out when the next NDP offset is not larger than the current
one.


Verified in a QEMU guest with a fault injector feeding the driver's
receive callback an NTB whose single NDP points at itself: the
unpatched driver spins in mhi_mbim_rx() with one CPU pinned at 100%
and the thread never returns. With this check the loop terminates
within one iteration.

Changes in v2: move the non-increasing check to the wNextNdpIndex
retrieval site, as suggested by Loic Poulain, instead of tracking
the previous offset in a separate variable.
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service (CPU exhaustion)
Action: Update Kernel
AI Analysis

Impact

The vulnerability is a logic flaw in the Linux kernel’s mhi_wwan_mbim driver that allows a modem to construct a cyclic or self‑referencing Network Data Path (NDP) chain. When the driver’s receive routine traverses the chain, the loop only terminates when the next offset is zero; it never checks that the offsets are strictly increasing. An attacker feeding a malformed NDP can cause the driver to spin forever on a single CPU core, consuming 100% of that core’s capacity. The impact is a denial‑of‑service that can render the system unresponsive if the affected driver is active.

Affected Systems

All Linux kernel builds that include the mhi_wwan_mbim driver are potentially affected. The specific kernel versions are not enumerated in the data, so any kernel containing the unpatched commit is at risk until the patch is applied.

Risk and Exploitability

The CVSS score is not provided, and EPSS data is unavailable, so the exact quantitative risk cannot be derived. However, the exploit requires interaction with the modem’s networking stack, which suggests a local or privilege‑escalated attacker could supply the malicious data. There is no evidence that automated exploits are currently in use or that the vulnerability is listed in CISA’s KEV catalog. The destructive potential of a CPU‑exhaustion loop is significant, especially on systems with limited cores or in multi‑tenant environments.

Generated by OpenCVE AI on October 6, 2026 at 11:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the patch for mhi_wwan_mbim (commit 19b5e8dd... or later).
  • If a kernel update is not immediately available, consider disabling or removing the mhi_wwan_mbim module until the patch is released.
  • For systems that must remain online, monitor the mhi_wwan_mbim driver for abnormal CPU usage and, if possible, throttle or isolate the network traffic to the modem to prevent a single malicious packet from triggering the loop.

Generated by OpenCVE AI on October 6, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-808

Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain The NDP traversal in mhi_mbim_rx() only stops when wNextNdpIndex is zero. Nothing requires the offsets to advance, so a modem that points an NDP at itself, or at an earlier NDP, keeps the loop spinning forever on one CPU. Break out when the next NDP offset is not larger than the current one. Verified in a QEMU guest with a fault injector feeding the driver's receive callback an NTB whose single NDP points at itself: the unpatched driver spins in mhi_mbim_rx() with one CPU pinned at 100% and the thread never returns. With this check the loop terminates within one iteration. Changes in v2: move the non-increasing check to the wNextNdpIndex retrieval site, as suggested by Loic Poulain, instead of tracking the previous offset in a separate variable.
Title net: wwan: mhi_wwan_mbim: guard against a cyclic NDP chain
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-06T08:45:09.277Z

Reserved: 2026-09-25T10:25:14.329Z

Link: CVE-2026-98237

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T09:18:11.500

Modified: 2026-10-06T09:18:11.500

Link: CVE-2026-98237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T12:00:15Z

Weaknesses