cbcvebase.
CVE-2026-23312
published 2026-03-25

CVE-2026-23312: In the Linux kernel, the following vulnerability has been resolved: net: usb: kaweth: validate USB endpoints The kaweth driver should validate that the device…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net: usb: kaweth: validate USB endpoints The kaweth driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3b5075e4ce97d1a1ce82ff3fb6308761987a48bb3b5075e4ce97d1a1ce82ff3fb6308761987a48bb
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6c986abd2a5033633c6e6f9dd135cf96b19c7fdf6c986abd2a5033633c6e6f9dd135cf96b19c7fdf
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7c7ebf5e45d2504d92ea294ac3828d58586491df7c7ebf5e45d2504d92ea294ac3828d58586491df
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 72f90f481c6a059680b9b976695d4cfb04fba1f372f90f481c6a059680b9b976695d4cfb04fba1f3
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f33e80d195a003b384620ee240f69092b519146bf33e80d195a003b384620ee240f69092b519146b
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 2795fc06e7652c0ba299d936c584d5e08b6b57a12795fc06e7652c0ba299d936c584d5e08b6b57a1
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0aae18e4638a7c1c579df92bc6edc36cedfaaa8c0aae18e4638a7c1c579df92bc6edc36cedfaaa8c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 4b063c002ca759d1b299988ee23f564c9609c8754b063c002ca759d1b299988ee23f564c9609c875
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 2.6.12 < 6.1.1676.1.167
linuxlinux_kernel>= 2.6.12.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17
linuxlinux_kernel>= 6.19 < 6.19.76.19.7
linuxlinux_kernel>= 6.19.0 < 6.19.76.19.7
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.2.0 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
linuxlinux_kernel>= 6.7.0 < 6.12.776.12.77

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_ubuntu7.1HIGH
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.