CVE-2026-23365

In the Linux kernel, the following vulnerability has been resolved: net: usb: kalmia: validate USB endpoints The kalmia driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.0:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

History

14 Jul 2026, 13:18

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-019113.html -
  • () https://cert-portal.siemens.com/productcert/html/ssa-082556.html -

24 Apr 2026, 18:47

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/011684cd18349aa4c52167c8ac37a0524169f48c - () https://git.kernel.org/stable/c/011684cd18349aa4c52167c8ac37a0524169f48c - Patch
References () https://git.kernel.org/stable/c/12c0243de0aee0ab27cc00932fd5edae65c1e3a2 - () https://git.kernel.org/stable/c/12c0243de0aee0ab27cc00932fd5edae65c1e3a2 - Patch
References () https://git.kernel.org/stable/c/185050b47df3d41e49f20ad01beea2e7b9cddaa7 - () https://git.kernel.org/stable/c/185050b47df3d41e49f20ad01beea2e7b9cddaa7 - Patch
References () https://git.kernel.org/stable/c/28a380bfa5bc7f6a9380b85e8eab919ee6ac1701 - () https://git.kernel.org/stable/c/28a380bfa5bc7f6a9380b85e8eab919ee6ac1701 - Patch
References () https://git.kernel.org/stable/c/51c20ea5f1555a984c041b0dbf56f00d41b9e652 - () https://git.kernel.org/stable/c/51c20ea5f1555a984c041b0dbf56f00d41b9e652 - Patch
References () https://git.kernel.org/stable/c/7bfda1a0be4caec3263753d567678451cef73a85 - () https://git.kernel.org/stable/c/7bfda1a0be4caec3263753d567678451cef73a85 - Patch
References () https://git.kernel.org/stable/c/c58b6c29a4c9b8125e8ad3bca0637e00b71e2693 - () https://git.kernel.org/stable/c/c58b6c29a4c9b8125e8ad3bca0637e00b71e2693 - Patch
References () https://git.kernel.org/stable/c/ff675bc5b3e8c356f9d993d65d0bae6ed0dc7459 - () https://git.kernel.org/stable/c/ff675bc5b3e8c356f9d993d65d0bae6ed0dc7459 - Patch
First Time Linux
Linux linux Kernel
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:3.0:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*

18 Apr 2026, 09:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/185050b47df3d41e49f20ad01beea2e7b9cddaa7 -
  • () https://git.kernel.org/stable/c/ff675bc5b3e8c356f9d993d65d0bae6ed0dc7459 -
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: net: usb: kalmia: validar puntos finales USB El controlador kalmia debería validar que el dispositivo que está sondeando tiene el número y los tipos adecuados de puntos finales USB que espera antes de que se vincule a él. Si un dispositivo malicioso no tuviera los mismos urbs, el controlador fallará más tarde cuando acceda ciegamente a estos puntos finales.

25 Mar 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 11:16

Updated : 2026-07-14 13:18


NVD link : CVE-2026-23365

Mitre link : CVE-2026-23365

CVE.ORG link : CVE-2026-23365


JSON object : View

Products Affected

linux

  • linux_kernel