Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23679

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 6.2

Описание

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

A flaw was found in libusb. An attacker can provide a specially crafted Universal Serial Bus (USB) configuration descriptor to applications using libusb. This malformed descriptor can lead to a null pointer dereference, causing the application to crash and resulting in a denial of service. This vulnerability can be exploited via virtualized USB passthrough, file-based descriptor parsing, or network sources.

Отчет

This Moderate flaw in libusb can lead to a denial of service when processing a specially crafted USB configuration descriptor. Exploitation requires an application to handle such a malformed descriptor, which can occur through virtualized USB passthrough, file-based parsing, or network sources. This issue primarily impacts system availability and does not enable arbitrary code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libusb1Fix deferred
Red Hat Enterprise Linux 6libusbOut of support scope
Red Hat Enterprise Linux 6libusb1Out of support scope
Red Hat Enterprise Linux 7libusbOut of support scope
Red Hat Enterprise Linux 8libusbFix deferred
Red Hat Enterprise Linux 9libusbFix deferred
Red Hat Hardened Imageslibusb1-main-1.0.30-1.hum1FixedRHSA-2026:2007521.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2482102libusb: libusb: Denial of Service via malformed USB configuration descriptor

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
2 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

CVSS3: 6.2
nvd
2 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

msrc
2 месяца назад

libusb < 1.0.30 NULL Pointer Dereference in parse_interface()

CVSS3: 6.2
debian
2 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulne ...

CVSS3: 6.2
github
2 месяца назад

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

6.2 Medium

CVSS3