CVE-2026-23290

ANALYSIS PENDING

net: usb: pegasus: validate USB endpoints

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: validate USB endpoints The pegasus driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.

Scores

EPSS 0.0003
EPSS Percentile 10.5%

Details

Status published
Products (24)
linux/Kernel 2.6.12 - 6.1.167linux
linux/Kernel 6.13.0 - 6.18.17linux
linux/Kernel 6.19.0 - 6.19.7linux
linux/Kernel 6.2.0 - 6.6.130linux
linux/Kernel 6.7.0 - 6.12.77linux
Linux/Linux < 2.6.12
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 11de1d3ae5565ed22ef1f89d73d8f2d00322c699
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 43d7c4114b1ec14f41f09306525d3b9382286fc1
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 7f8505c7ce3f186ef9d2495f3c0bd6ad6fce999f
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 95556b4e879711693c9865ba0938c148f62d5ea4
... and 14 more
Published Mar 25, 2026
Tracked Since Mar 25, 2026