Linuxsecurity
SUSE libusb-1_0 NULL Pointer Vulnerability Advisory
Article Content
A NULL pointer dereference vulnerability (CVE-2026-23679) has been identified in libusb-1_0, affecting multiple SUSE Linux distributions. This flaw allows attackers to crash applications by providing malformed USB configuration descriptors. The vulnerability has a moderate severity rating with a CVSS score of 4.0. Affected systems include openSUSE Leap 15.4 and SUSE Linux Enterprise Micro versions 5.3 and 5.4. Users are advised to apply the available patches immediately to mitigate any risks. The vulnerability was published on May 27, 2026, and is now addressed with patch SUSE-2026-4050. The advisory emphasizes the importance of keeping systems updated to prevent exploitation.
Key Points: • CVE-2026-23679 allows application crashes via malformed USB descriptors. • Affected systems include openSUSE Leap 15.4 and SUSE Linux Enterprise Micro. • Patches are available and should be applied immediately.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.