SUSE libusb-1_0 NULL Pointer Vulnerability Advisory

SUSE libusb-1_0 NULL Pointer Vulnerability Advisory

First seen 8 Sep 2026, 12:03 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

A NULL pointer dereference vulnerability (CVE-2026-23679) has been identified in libusb-1_0, affecting multiple SUSE Linux distributions. This flaw allows attackers to crash applications by providing malformed USB configuration descriptors. The vulnerability has a moderate severity rating with a CVSS score of 4.0. Affected systems include openSUSE Leap 15.4 and SUSE Linux Enterprise Micro versions 5.3 and 5.4. Users are advised to apply the available patches immediately to mitigate any risks. The vulnerability was published on May 27, 2026, and is now addressed with patch SUSE-2026-4050. The advisory emphasizes the importance of keeping systems updated to prevent exploitation.

Key Points: • CVE-2026-23679 allows application crashes via malformed USB descriptors. • Affected systems include openSUSE Leap 15.4 and SUSE Linux Enterprise Micro. • Patches are available and should be applied immediately.

Ask AI about this cluster

Timeline

2026-05-27
CVE-2026-23679 published
A NULL pointer dereference vulnerability in libusb-1_0 was disclosed, allowing application crashes.
Linuxsecurity
2026-09-07
Patch released for libusb-1_0
SUSE released patch SUSE-2026-4050 to address the NULL pointer dereference vulnerability.
Linuxsecurity
2026-09-08
Advisory published
SUSE issued an advisory urging users to apply the patch to mitigate the vulnerability.
Linuxsecurity