openSUSE-SU-2026:21783-1
Dashboard / Vulnerabilities / openSUSE-SU-2026:21783-1
openSUSE-SU-2026:21783-1
Summary: Security update for libusb-1_0
Details: This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667).
References: , https://bugzilla.suse.com/1266664, https://bugzilla.suse.com/1266667, https://www.suse.com/security/cve/CVE-2026-23679, https://www.suse.com/security/cve/CVE-2026-47104
Affected packages
Package
Name: libusb-1_0
Purl: pkg:rpm/opensuse/libusb-1_0&distro=openSUSE%20Leap%2016.0
Affected ranges
Type: ECOSYSTEM
Events:
