Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: libusb1: * libusb1-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-devel-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-devel-doc-1.0.30-1.hum1 (noarch) * libusb1-tests-examples-1.0.30-1.hum1 (aarch64, x86_64) * mingw32-libusb1-1.0.30-1.hum1 (aarch64, x86_64) * mingw64-libusb1-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-1.0.30-1.hum1.src (src)
AI Analysis
Technical Summary
CVE-2026-23679 is a denial of service vulnerability in libusb where processing a malformed USB configuration descriptor causes a null pointer dereference, crashing the application. Exploitation requires the application to handle such malformed descriptors, which can occur through virtualized USB passthrough, file parsing, or network sources. The vulnerability affects Red Hat Hardened Images RPMs, specifically libusb1 packages for aarch64 and x86_64 architectures. The flaw impacts system availability but does not enable arbitrary code execution. Red Hat has issued an update (libusb1-1.0.30-1.hum1) to fix this issue.
Potential Impact
The vulnerability causes a denial of service by crashing applications that process malformed USB configuration descriptors via libusb. It affects system availability but does not compromise confidentiality or integrity. There is no indication of arbitrary code execution or privilege escalation. Exploitation requires local or controlled input of malformed USB descriptors, such as through virtualized USB passthrough or file/network-based descriptor parsing.
Mitigation Recommendations
Red Hat has released updated libusb1 packages (version 1.0.30-1.hum1) for affected architectures to fix this vulnerability. Users of Red Hat Hardened Images should apply this update to remediate the issue. No additional mitigations are specified or required beyond applying the official update.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: libusb1: * libusb1-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-devel-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-devel-doc-1.0.30-1.hum1 (noarch) * libusb1-tests-examples-1.0.30-1.hum1 (aarch64, x86_64) * mingw32-libusb1-1.0.30-1.hum1 (aarch64, x86_64) * mingw64-libusb1-1.0.30-1.hum1 (aarch64, x86_64) * libusb1-1.0.30-1.hum1.src (src)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-23679 is a denial of service vulnerability in libusb where processing a malformed USB configuration descriptor causes a null pointer dereference, crashing the application. Exploitation requires the application to handle such malformed descriptors, which can occur through virtualized USB passthrough, file parsing, or network sources. The vulnerability affects Red Hat Hardened Images RPMs, specifically libusb1 packages for aarch64 and x86_64 architectures. The flaw impacts system availability but does not enable arbitrary code execution. Red Hat has issued an update (libusb1-1.0.30-1.hum1) to fix this issue.
Potential Impact
The vulnerability causes a denial of service by crashing applications that process malformed USB configuration descriptors via libusb. It affects system availability but does not compromise confidentiality or integrity. There is no indication of arbitrary code execution or privilege escalation. Exploitation requires local or controlled input of malformed USB descriptors, such as through virtualized USB passthrough or file/network-based descriptor parsing.
Mitigation Recommendations
Red Hat has released updated libusb1 packages (version 1.0.30-1.hum1) for affected architectures to fix this vulnerability. Users of Red Hat Hardened Images should apply this update to remediate the issue. No additional mitigations are specified or required beyond applying the official update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-23679
- Cve Count
- 1
Threat ID: 6a18ab86e29bf47b50288fa0
Added to database: 05/28/2026, 20:54:30 UTC
Last enriched: 08/16/2026, 17:45:36 UTC
Last updated: 09/10/2026, 19:36:52 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.