PT-2026-43972 · Libusb · Libusb

·

CVE-2026-47104

·

Published

2026-05-27

·

Updated

2026-09-07

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libusb versions prior to 1.0.30
Description A one-byte out-of-bounds read exists in the parse iad array() function within descriptor.c. This occurs when a malformed USB descriptor is supplied where the bLength equals the size minus one, causing the bounds check to utilize the original buffer size rather than the remaining size. In virtualized environments with USB passthrough, attackers can use the functions libusb get active interface association descriptors or libusb get interface association descriptors to provide crafted descriptors, reading one byte past the end of the malloc allocation and triggering a denial of service.
Recommendations Update to version 1.0.30 or later.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-88409
AZL-89156
CVE-2026-47104
ECHO-A3A1-40F9-FC5F
JLSEC-2026-666
OPENSUSE-SU-2026:21783-1
PYSEC-2026-3979

Affected Products

Libusb