CVE-2026-23312

In the Linux kernel, the following vulnerability has been resolved: net: usb: kaweth: validate USB endpoints The kaweth driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*

History

26 May 2026, 15:02

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:2.6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/0aae18e4638a7c1c579df92bc6edc36cedfaaa8c - () https://git.kernel.org/stable/c/0aae18e4638a7c1c579df92bc6edc36cedfaaa8c - Patch
References () https://git.kernel.org/stable/c/2795fc06e7652c0ba299d936c584d5e08b6b57a1 - () https://git.kernel.org/stable/c/2795fc06e7652c0ba299d936c584d5e08b6b57a1 - Patch
References () https://git.kernel.org/stable/c/3b5075e4ce97d1a1ce82ff3fb6308761987a48bb - () https://git.kernel.org/stable/c/3b5075e4ce97d1a1ce82ff3fb6308761987a48bb - Patch
References () https://git.kernel.org/stable/c/4b063c002ca759d1b299988ee23f564c9609c875 - () https://git.kernel.org/stable/c/4b063c002ca759d1b299988ee23f564c9609c875 - Patch
References () https://git.kernel.org/stable/c/6c986abd2a5033633c6e6f9dd135cf96b19c7fdf - () https://git.kernel.org/stable/c/6c986abd2a5033633c6e6f9dd135cf96b19c7fdf - Patch
References () https://git.kernel.org/stable/c/72f90f481c6a059680b9b976695d4cfb04fba1f3 - () https://git.kernel.org/stable/c/72f90f481c6a059680b9b976695d4cfb04fba1f3 - Patch
References () https://git.kernel.org/stable/c/7c7ebf5e45d2504d92ea294ac3828d58586491df - () https://git.kernel.org/stable/c/7c7ebf5e45d2504d92ea294ac3828d58586491df - Patch
References () https://git.kernel.org/stable/c/f33e80d195a003b384620ee240f69092b519146b - () https://git.kernel.org/stable/c/f33e80d195a003b384620ee240f69092b519146b - Patch

18 Apr 2026, 09:16

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: net: usb: kaweth: validar los puntos finales USB El controlador kaweth debería validar que el dispositivo que está sondeando tiene el número y los tipos adecuados de puntos finales USB que espera antes de vincularse a él. Si un dispositivo malicioso no tuviera los mismos urbs, el controlador se bloqueará más adelante cuando acceda ciegamente a estos puntos finales.
References
  • () https://git.kernel.org/stable/c/3b5075e4ce97d1a1ce82ff3fb6308761987a48bb -
  • () https://git.kernel.org/stable/c/6c986abd2a5033633c6e6f9dd135cf96b19c7fdf -

25 Mar 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 11:16

Updated : 2026-05-26 15:02


NVD link : CVE-2026-23312

Mitre link : CVE-2026-23312

CVE.ORG link : CVE-2026-23312


JSON object : View

Products Affected

linux

  • linux_kernel