SUSE-SU-2026:23501-1
Dashboard / Vulnerabilities / SUSE-SU-2026:23501-1
SUSE-SU-2026:23501-1
Summary: Security update for libusb-1_0
Details: This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667).
References: https://www.suse.com/support/update/announcement/2026/suse-su-202623501-1/, https://bugzilla.suse.com/1266664, https://bugzilla.suse.com/1266667, https://www.suse.com/security/cve/CVE-2026-23679, https://www.suse.com/security/cve/CVE-2026-47104
Affected packages
Package
Name: libusb-1_0
Purl: pkg:rpm/suse/libusb-1_0&distro=SUSE%20Linux%20Micro%206.2
Affected ranges
Type: ECOSYSTEM
Events:
