Skip to main content
EPSS 0.2%top 92%

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

0
Medium
Published: 05/21/2026 (05/21/2026, 09:17:53 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: libusb1: * libusb1-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-devel-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-devel-doc-1.0.30-1.hum1 (noarch) * libusb1-tests-examples-1.0.30-1.hum1 (aarch64, x86_64) * mingw32-libusb1-1.0.30-1.hum1 (aarch64, x86_64) * mingw64-libusb1-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-1.0.30-1.hum1.src (src)

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64libusb1-main@aarch64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 17:45:36 UTC

Technical Analysis

CVE-2026-23679 is a denial of service vulnerability in libusb where processing a malformed USB configuration descriptor causes a null pointer dereference, crashing the application. Exploitation requires the application to handle such malformed descriptors, which can occur through virtualized USB passthrough, file parsing, or network sources. The vulnerability affects Red Hat Hardened Images RPMs, specifically libusb1 packages for aarch64 and x86_64 architectures. The flaw impacts system availability but does not enable arbitrary code execution. Red Hat has issued an update (libusb1-1.0.30-1.hum1) to fix this issue.

Potential Impact

The vulnerability causes a denial of service by crashing applications that process malformed USB configuration descriptors via libusb. It affects system availability but does not compromise confidentiality or integrity. There is no indication of arbitrary code execution or privilege escalation. Exploitation requires local or controlled input of malformed USB descriptors, such as through virtualized USB passthrough or file/network-based descriptor parsing.

Mitigation Recommendations

Red Hat has released updated libusb1 packages (version 1.0.30-1.hum1) for affected architectures to fix this vulnerability. Users of Red Hat Hardened Images should apply this update to remediate the issue. No additional mitigations are specified or required beyond applying the official update.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_vex
Csaf Version
2.0
Publisher
Microsoft Security Response Center
Advisory Id
msrc_CVE-2026-23679
Cve Count
1

Threat ID: 6a18ab86e29bf47b50288fa0

Added to database: 05/28/2026, 20:54:30 UTC

Last enriched: 08/16/2026, 17:45:36 UTC

Last updated: 09/10/2026, 19:36:52 UTC

Views: 48

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses