Описание
Security update for libusb-1_0
This update for libusb-1_0 fixes the following issue:
- CVE-2026-23679: NULL pointer dereference in
parse_interface()allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664).
Список пакетов
Container bci/spack:latest
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
Container suse/kiosk/firefox-esr:latest
Container suse/rmt-server:latest
Container suse/sle-micro-rancher/5.3:latest
Container suse/sle-micro-rancher/5.4:latest
Container suse/sle-micro/5.3/toolbox:latest
Container suse/sle-micro/5.4/toolbox:latest
Container suse/sle-micro/5.5/toolbox:latest
Container suse/sle-micro/5.5:latest
Container suse/sle-micro/base-5.5:latest
Container suse/sle15:latest
Image SLES15-SP6-SAP
Image SLES15-SP6-SAP-Azure
Image SLES15-SP6-SAPCAL
Image SLES15-SP6-SAPCAL-Azure
Image SLES15-SP7-SAPCAL-Azure
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Micro 5.4
SUSE Linux Enterprise Micro 5.5
SUSE Linux Enterprise Module for Basesystem 15 SP7
SUSE Linux Enterprise Module for Package Hub 15 SP7
Ссылки
- Link for SUSE-SU-2026:4050-1
- E-Mail link for SUSE-SU-2026:4050-1
- SUSE Security Ratings
- SUSE Bug 1266664
- SUSE CVE CVE-2026-23679 page
Описание
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.
Затронутые продукты
Ссылки
- CVE-2026-23679
- SUSE Bug 1266664