VYPR
Medium severity6.2NVD Advisory· Published May 27, 2026· Updated Jul 14, 2026

CVE-2026-23679

CVE-2026-23679

Description

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Libusb/Libusb2 versions
    cpe:2.3:a:libusb:libusb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:libusb:libusb:*:*:*:*:*:*:*:*range: <1.0.30
    • (no CPE)range: <1.0.30

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.