VDB

CVE-2026-23679

CVE-2026-23679 PUBLISHED CVSS 6.9 MEDIUM

Reported by VulnCheck · Published May 27, 2026

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

Risk Scores

CVSS 4.0
6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
libusblibusb0
libusblibusb0, 0, 0

Timeline

  • May 27, 2026 CVE Published
  • May 28, 2026 EPSS Score
  • May 29, 2026 EPSS Score
  • May 30, 2026 EPSS Score
  • May 31, 2026 EPSS Score
  • Jun 1, 2026 EPSS Score
  • Jun 1, 2026 Security Advisory
  • Jun 5, 2026 EPSS Score
  • Jun 10, 2026 Coalition ESS Score
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score

References

  • release-notes
  • issue-tracking
  • issue-tracking
  • patch
  • third-party-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›