libusb
Python binding for the libusb C library.
Activity
- Latest release
- 4d ago
- Total releases
- 32
- Cadence
- ~2 months
- Last 12 months
- 8
Reach
- Stars
- 44
Details
- License
- Zlib
- First release
- Nov 09, 2018
| Version | Released | |
|---|---|---|
1.0.30
patch
| ||
1.0.30rc2
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.30rc1
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.29.post7
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.29.post6
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.29.post4
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.29.post3
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.29.post1
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.29
patch
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.28.post2
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.28.post1
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.28
patch
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.27.post4
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.27.post3
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.27.post2
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.27.post1
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.27
patch
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.26
initial
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.26rc4
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.26rc2
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.26b5
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.26b4
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.26b3
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.26b2
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.24b3
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.24b1
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.23b7
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.23b1
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.22b9
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.22b8
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.22b4
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev | ||
1.0.22b2
pre
2 CVEs
CVE-2026-47104
PYSEC-2026-3979
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying a malformed USB descriptor whose bLength equals size minus one, causing the bounds check to use the original buffer size instead of the remaining size. Attackers in virtualized environments with USB passthrough can supply crafted descriptors through libusb_get_active_interface_association_descriptors or libusb_get_interface_association_descriptors to read one byte past the end of the malloc allocation, resulting in a denial of service. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev
CVE-2026-23679
PYSEC-2026-3978
May 27, 2026
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an interface claims bNumEndpoints greater than zero but is followed by a class-specific descriptor whose bLength exceeds the remaining buffer size, causing parse_interface() to return early without allocating the endpoint array. Attackers can exploit this flaw through libusb_get_active_config_descriptor or libusb_get_config_descriptor by providing crafted descriptors via virtualized USB passthrough, file-based descriptor parsing, or network sources, causing any application iterating over endpoints to dereference a NULL endpoint pointer and crash. Affected versions
1.0.22b2
1.0.22b4
1.0.22b8
1.0.22b9
1.0.23b1
1.0.23b7
1.0.24b1
1.0.24b3
1.0.26
1.0.26b2
1.0.26b3
1.0.26b4
+ 19 more Show less
1.0.26b5
1.0.26rc2
1.0.26rc4
1.0.27
1.0.27.post1
1.0.27.post2
1.0.27.post3
1.0.27.post4
1.0.28
1.0.28.post1
1.0.28.post2
1.0.29
1.0.29.post1
1.0.29.post3
1.0.29.post4
1.0.29.post6
1.0.29.post7
1.0.30rc1
1.0.30rc2
Fixed in
1.0.30
References
Updated Sep 11, 2026 · Source: OSV.dev |