Executive brief
A vulnerability in the Linux kernel's Pegasus USB network driver could allow a system crash when a specially crafted or malicious USB device is plugged in. The driver fails to verify that the connected device has the expected communication channels before attempting to use them. This could be used by an attacker with physical access to the machine to cause a denial-of-service by crashing the operating system.
Technical details
A vulnerability exists in the 'pegasus' USB Ethernet driver (drivers/net/usb/pegasus.c) within the Linux kernel due to insufficient validation of USB endpoints during device probing. The driver blindly accesses USB Request Blocks (URBs) without verifying that the device provides the expected number and types of endpoints (bulk and interrupt). An attacker can exploit this by connecting a malicious USB device that lacks the expected endpoints, triggering a null pointer dereference or similar memory corruption that results in a kernel panic. Patches have been released across multiple stable kernel branches to implement proper endpoint checking using 'usb_check_bulk_endpoints' and 'usb_check_int_endpoints'.
Affected products
- Linux Linux Kernel versions from 2.6.12.1 up to 5.10.253; 5.11 to 5.15.203; 5.16 to 6.1.167; 6.2 to 6.6.130; 6.7 to 6.12.77; 6.13 to 6.18.17; 6.19 to 6.19.7
Timeline
- 2026-03-25: disclosed: Initial disclosure and publication of CVE-2026-23290
- 2026-02-25: patched: Initial patch committed to the Linux kernel tree
References
- https://git.kernel.org/stable/c/11de1d3ae5565ed22ef1f89d73d8f2d00322c699
- https://git.kernel.org/stable/c/43d7c4114b1ec14f41f09306525d3b9382286fc1
- https://git.kernel.org/stable/c/7f8505c7ce3f186ef9d2495f3c0bd6ad6fce999f
- https://git.kernel.org/stable/c/95556b4e879711693c9865ba0938c148f62d5ea4
- https://git.kernel.org/stable/c/af7369ae572f53cb701731a4289ec3b3889bc501
- https://git.kernel.org/stable/c/c3f1672eaea68c5cb6e1ec081cdb92045453218f
- https://git.kernel.org/stable/c/d5d9086211877361f1bda44a0aec538ddb04042a