PT-2026-43696 · Libusb · Libusb

·

CVE-2026-23679

·

Published

2026-04-25

·

Updated

2026-09-07

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libusb versions prior to 1.0.30
Description A NULL pointer dereference occurs when a malformed USB configuration descriptor is supplied. Specifically, if an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor with a bLength exceeding the remaining buffer size, the parse interface() function returns early without allocating the endpoint array. This can be exploited via the functions libusb get active config descriptor or libusb get config descriptor by providing crafted descriptors through network sources, file-based descriptor parsing, or virtualized USB passthrough, leading to an application crash when iterating over endpoints.
Recommendations Update to version 1.0.30 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-88412
AZL-88791
AZL-89153
BDU:2026-12832
CVE-2026-23679
ECHO-9B94-4C06-2947
JLSEC-2026-665
OESA-2026-2742
OESA-2026-2743
OPENSUSE-SU-2026:21783-1
PYSEC-2026-3978
RHSA-2026:20075

Affected Products

Libusb