What is CVE-2026-12052?
CVE-2026-12052 is a vulnerability in the USB device-side CDC NCM class control handler where the response for GET_NTB_PARAMETERS copies data into a fixed-size 28-byte buffer, potentially causing a buffer overflow. This flaw affects systems with the vulnerable USB stack and could allow an attacker with physical access to cause denial-of-service or execute arbitrary code via a malicious USB device. Affected users should apply the vendor-provided patches promptly.
Azərbaycanca: CVE-2026-12052, USB cihaz tərəfində CDC NCM sinfinin idarəedici prosedurunda aşkar edilmiş boşluqdur. Bu zəiflik GET_NTB_PARAMETERS sorğusuna verilən cavab zamanı "struct ntb_parameters" üçün nəzərdə tutulmuş 28 baytlıq sahəyə daha böyük məlumat kopyalanması nəticəsində bufer daşmasına səbəb olur. Təsirə məruz qalan sistemlərdə hücumçu fiziki giriş əldə edərək xüsusi hazırlanmış USB cihazı vasitəsilə DoS hücumu həyata keçirə və ya potensial olaraq kod icra edə bilər, ona görə də təchizatçı tərəfindən təqdim olunan zəruri yamaları tətbiq etmək vacibdir.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What is CVE-2026-12052?
This CVE describes a vulnerability in the USB device-side CDC NCM class control handler, where a buffer overflow can occur because the response to a GET_NTB_PARAMETERS request copies data into a fixed-size 28-byte buffer beyond its capacity.
What does an attacker need to exploit this vulnerability?
The attacker requires physical access to the affected system and must connect a specially crafted malicious USB device.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.