In the Linux kernel, the following vulnerability has been resolved: net: usb: kaweth: validate USB endpoints The kaweth driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.
CVE-2026-23312
NONE
EPSS 0.03%
Updated Mar 25, 2026
Linux
https://git.kernel.org/stable/c/0aae18e4638a7c1c579df92bc6edc36cedfaaa8c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/2795fc06e7652c0ba299d936c584d5e08b6b57a1
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/4b063c002ca759d1b299988ee23f564c9609c875
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/72f90f481c6a059680b9b976695d4cfb04fba1f3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/7c7ebf5e45d2504d92ea294ac3828d58586491df
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/stable/c/f33e80d195a003b384620ee240f69092b519146b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVE Details
CVE ID
CVE-2026-23312
Published Date
Mar 25, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.03%
Likelihood of exploitation in next 30 days
Percentile:
9.2th percentile (higher than 9.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory