CVE-2026-23290

In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: validate USB endpoints The pegasus driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*

History

29 May 2026, 15:10

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
References () https://git.kernel.org/stable/c/11de1d3ae5565ed22ef1f89d73d8f2d00322c699 - () https://git.kernel.org/stable/c/11de1d3ae5565ed22ef1f89d73d8f2d00322c699 - Patch
References () https://git.kernel.org/stable/c/43d7c4114b1ec14f41f09306525d3b9382286fc1 - () https://git.kernel.org/stable/c/43d7c4114b1ec14f41f09306525d3b9382286fc1 - Patch
References () https://git.kernel.org/stable/c/7f8505c7ce3f186ef9d2495f3c0bd6ad6fce999f - () https://git.kernel.org/stable/c/7f8505c7ce3f186ef9d2495f3c0bd6ad6fce999f - Patch
References () https://git.kernel.org/stable/c/95556b4e879711693c9865ba0938c148f62d5ea4 - () https://git.kernel.org/stable/c/95556b4e879711693c9865ba0938c148f62d5ea4 - Patch
References () https://git.kernel.org/stable/c/af7369ae572f53cb701731a4289ec3b3889bc501 - () https://git.kernel.org/stable/c/af7369ae572f53cb701731a4289ec3b3889bc501 - Patch
References () https://git.kernel.org/stable/c/c3f1672eaea68c5cb6e1ec081cdb92045453218f - () https://git.kernel.org/stable/c/c3f1672eaea68c5cb6e1ec081cdb92045453218f - Patch
References () https://git.kernel.org/stable/c/d5d9086211877361f1bda44a0aec538ddb04042a - () https://git.kernel.org/stable/c/d5d9086211877361f1bda44a0aec538ddb04042a - Patch
References () https://git.kernel.org/stable/c/ee31ec8cf1eafeefa85ef934ba688d27f88bf0e2 - () https://git.kernel.org/stable/c/ee31ec8cf1eafeefa85ef934ba688d27f88bf0e2 - Patch

18 Apr 2026, 09:16

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: net: usb: pegasus: validar puntos finales USB El controlador pegasus debería validar que el dispositivo que está sondeando tiene el número y tipos adecuados de puntos finales USB que espera antes de que se vincule a él. Si un dispositivo malicioso no tuviera los mismos urbs, el controlador fallará más tarde cuando acceda ciegamente a estos puntos finales.
References
  • () https://git.kernel.org/stable/c/af7369ae572f53cb701731a4289ec3b3889bc501 -
  • () https://git.kernel.org/stable/c/d5d9086211877361f1bda44a0aec538ddb04042a -

25 Mar 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 11:16

Updated : 2026-05-29 15:10


NVD link : CVE-2026-23290

Mitre link : CVE-2026-23290

CVE.ORG link : CVE-2026-23290


JSON object : View

Products Affected

linux

  • linux_kernel