DevSecOps Toolkit

CVE record

CVE-2026-43430

MEDIUMCVSS 4.7

In the Linux kernel, the following vulnerability has been resolved: usb: yurex: fix race in probe The bbu member of the descriptor must be set to the value standing for uninitialized values before the URB whose completion handler sets bbu is submitted. Otherwise there is a window during which probing can overwrite already retrieved data.

Vulnerability metadata

Published
2026-05-08T09:46:55.243Z
Modified
2026-05-20T12:52:23.643Z
EPSS
Not available
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

References