PatchSiren cyber security CVE debrief
CVE-2026-23365 Linux CVE debrief
The Linux kernel has a vulnerability in the net: usb: kalmia module. The kalmia driver does not validate the USB endpoints of a device before binding to it, which can cause a crash if a malicious device is used. This vulnerability has been resolved by adding endpoint validation. Affected users should validate their systems and apply patches if necessary. The vulnerability requires a malicious device to be connected to the system, and the impact is considered medium priority.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Users of Linux kernel versions 3.0.1 to 6.19.7, and 7.0 rc1 to rc7, should validate their systems for this vulnerability and apply patches if necessary. System administrators and security teams responsible for Linux-based systems should review their deployments and ensure that necessary mitigations are in place. This vulnerability may impact system stability and security if not properly addressed.
Technical summary
The kalmia driver in the Linux kernel does not validate the number and types of USB endpoints of a device before binding to it. This can lead to a crash if a malicious device with a different number or type of endpoints is used. The vulnerability has been resolved by adding endpoint validation to the kalmia driver. Affected Linux kernel versions include 3.0.1 to 6.19.7, and 7.0 rc1 to rc7. Users should review their system configurations and apply patches to fix the vulnerability.
Defensive priority
Medium priority, as the vulnerability requires a malicious device to be connected to the system.
Recommended defensive actions
- Validate the USB endpoints of devices before binding to them
- Apply patches to the Linux kernel to fix the vulnerability
- Monitor systems for potential crashes or issues with USB devices
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability was resolved by adding endpoint validation to the kalmia driver. The Linux kernel versions 3.0.1 to 6.19.7, and 7.0 rc1 to rc7, are affected. Further verification is needed to confirm the scope of affected deployments and to apply patches or mitigations as necessary. Evidence limits suggest that additional details may be required to fully understand the vulnerability and its impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23365 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23365
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23365 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23365
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/011684cd18349aa4c52167c8ac37a0524169f48c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/12c0243de0aee0ab27cc00932fd5edae65c1e3a2
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/185050b47df3d41e49f20ad01beea2e7b9cddaa7
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/28a380bfa5bc7f6a9380b85e8eab919ee6ac1701
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/51c20ea5f1555a984c041b0dbf56f00d41b9e652
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7bfda1a0be4caec3263753d567678451cef73a85
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c58b6c29a4c9b8125e8ad3bca0637e00b71e2693
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.