PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23365 Linux CVE debrief

The Linux kernel has a vulnerability in the net: usb: kalmia module. The kalmia driver does not validate the USB endpoints of a device before binding to it, which can cause a crash if a malicious device is used. This vulnerability has been resolved by adding endpoint validation. Affected users should validate their systems and apply patches if necessary. The vulnerability requires a malicious device to be connected to the system, and the impact is considered medium priority.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Users of Linux kernel versions 3.0.1 to 6.19.7, and 7.0 rc1 to rc7, should validate their systems for this vulnerability and apply patches if necessary. System administrators and security teams responsible for Linux-based systems should review their deployments and ensure that necessary mitigations are in place. This vulnerability may impact system stability and security if not properly addressed.

Technical summary

The kalmia driver in the Linux kernel does not validate the number and types of USB endpoints of a device before binding to it. This can lead to a crash if a malicious device with a different number or type of endpoints is used. The vulnerability has been resolved by adding endpoint validation to the kalmia driver. Affected Linux kernel versions include 3.0.1 to 6.19.7, and 7.0 rc1 to rc7. Users should review their system configurations and apply patches to fix the vulnerability.

Defensive priority

Medium priority, as the vulnerability requires a malicious device to be connected to the system.

Recommended defensive actions

  • Validate the USB endpoints of devices before binding to them
  • Apply patches to the Linux kernel to fix the vulnerability
  • Monitor systems for potential crashes or issues with USB devices
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was resolved by adding endpoint validation to the kalmia driver. The Linux kernel versions 3.0.1 to 6.19.7, and 7.0 rc1 to rc7, are affected. Further verification is needed to confirm the scope of affected deployments and to apply patches or mitigations as necessary. Evidence limits suggest that additional details may be required to fully understand the vulnerability and its impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23365 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23365

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23365 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23365

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/011684cd18349aa4c52167c8ac37a0524169f48c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/12c0243de0aee0ab27cc00932fd5edae65c1e3a2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/185050b47df3d41e49f20ad01beea2e7b9cddaa7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/28a380bfa5bc7f6a9380b85e8eab919ee6ac1701

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/51c20ea5f1555a984c041b0dbf56f00d41b9e652

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7bfda1a0be4caec3263753d567678451cef73a85

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c58b6c29a4c9b8125e8ad3bca0637e00b71e2693

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.