PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23312 Linux CVE debrief

A vulnerability in the Linux kernel's kaweth USB network driver allows a local attacker to cause a denial of service through a malicious USB device. The driver fails to validate USB endpoints during device probing, leading to null pointer dereferences when accessing expected URBs. The issue affects Linux kernel versions from 2.6.12 through 6.19.7, with patches available for all supported stable branches. This vulnerability requires physical access or the ability to attach a malicious USB device to the target system.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-25
Original CVE updated
2026-05-26
Advisory published
2026-03-25
Advisory updated
2026-05-26

Who should care

System administrators managing Linux workstations and servers with USB ports accessible to untrusted users; security teams responsible for physical security controls; organizations using embedded Linux systems with exposed USB interfaces.

Technical summary

The kaweth driver in the Linux kernel's networking USB subsystem does not validate that a probed USB device has the expected number and types of endpoints before binding to it. When a malicious device lacking the expected URBs (USB Request Blocks) is attached, the driver later dereferences null pointers when attempting to access these endpoints, resulting in a kernel crash. The vulnerability is local, requires low privileges, and has high availability impact per CVSS 3.1 scoring.

Defensive priority

medium

Recommended defensive actions

  • Apply kernel updates from your Linux distribution that include fixes for CVE-2026-23312. Patches are available for stable branches 5.10.253+, 5.15.203+, 6.1.167+, 6.6.130+, 6.12.77+, 6.18.17+, and 6.19.7+.
  • Restrict physical access to systems to prevent attachment of untrusted USB devices.
  • Consider disabling the kaweth driver via kernel module blacklist if the Kawasaki LSI KL5KUSB101-based USB Ethernet adapter is not required: add 'blacklist kaweth' to /etc/modprobe.d/blacklist.conf or equivalent.
  • Monitor for unexpected kernel crashes or USB device enumeration failures that may indicate exploitation attempts.
  • Review system logs for suspicious USB device attachments, particularly unknown vendor/device IDs claiming to be kaweth-compatible hardware.

Evidence notes

CVE published 2026-03-25; modified 2026-05-26. NVD analyzed status. Multiple stable kernel patches released. CVSS 3.1 score 5.5 (MEDIUM) with vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H indicating local attack vector with low attack complexity and high availability impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23312 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23312

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23312 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23312

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0aae18e4638a7c1c579df92bc6edc36cedfaaa8c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2795fc06e7652c0ba299d936c584d5e08b6b57a1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3b5075e4ce97d1a1ce82ff3fb6308761987a48bb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4b063c002ca759d1b299988ee23f564c9609c875

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6c986abd2a5033633c6e6f9dd135cf96b19c7fdf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/72f90f481c6a059680b9b976695d4cfb04fba1f3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7c7ebf5e45d2504d92ea294ac3828d58586491df

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.