Описание
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.
A flaw was found in libusb. An attacker can provide a specially crafted Universal Serial Bus (USB) configuration descriptor to applications using libusb. This malformed descriptor can lead to a null pointer dereference, causing the application to crash and resulting in a denial of service. This vulnerability can be exploited via virtualized USB passthrough, file-based descriptor parsing, or network sources.
Отчет
This Moderate flaw in libusb can lead to a denial of service when processing a specially crafted USB configuration descriptor. Exploitation requires an application to handle such a malformed descriptor, which can occur through virtualized USB passthrough, file-based parsing, or network sources. This issue primarily impacts system availability and does not enable arbitrary code execution.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | libusb1 | Fix deferred | ||
| Red Hat Enterprise Linux 6 | libusb | Out of support scope | ||
| Red Hat Enterprise Linux 6 | libusb1 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | libusb | Out of support scope | ||
| Red Hat Enterprise Linux 8 | libusb | Fix deferred | ||
| Red Hat Enterprise Linux 9 | libusb | Fix deferred | ||
| Red Hat Hardened Images | libusb1-main-1.0.30-1.hum1 | Fixed | RHSA-2026:20075 | 21.05.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
6.2 Medium
CVSS3
Связанные уязвимости
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.
libusb before version 1.0.30 contains a NULL pointer dereference vulne ...
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.
6.2 Medium
CVSS3