{"id":"CVE-2026-43430","summary":"usb: yurex: fix race in probe","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: yurex: fix race in probe\n\nThe bbu member of the descriptor must be set to the value\nstanding for uninitialized values before the URB whose\ncompletion handler sets bbu is submitted. Otherwise there is\na window during which probing can overwrite already retrieved\ndata.","modified":"2026-07-22T18:14:54.560102655Z","published":"2026-05-08T14:22:02.458Z","related":["SUSE-SU-2026:3130-1","SUSE-SU-2026:3166-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43430.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/3cec135415a89723e2d38e1c8cc5098203355965"},{"type":"WEB","url":"https://git.kernel.org/stable/c/687d26d43a5aaf44323ce7d601cf242bb87e9559"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7a875c09899ba0404844abfd8f0d54cdc481c151"},{"type":"WEB","url":"https://git.kernel.org/stable/c/939e3d17b843b0bae70467fef4481069d73c8520"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a41d3d9202e951995cfac6248c565423079c71fa"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a7934d7202a39c3160aa30521c382c7b744ae4a2"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a8b3b3d730acea1640bc89465f2832cf06a1e13a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af83e92c329f11139d5eea2b5b7b83c26c3f67e7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43430.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43430"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6bc235a2e24a5ef677daee3fd4f74f6cd643e23c"},{"fixed":"a7934d7202a39c3160aa30521c382c7b744ae4a2"},{"fixed":"a8b3b3d730acea1640bc89465f2832cf06a1e13a"},{"fixed":"687d26d43a5aaf44323ce7d601cf242bb87e9559"},{"fixed":"939e3d17b843b0bae70467fef4481069d73c8520"},{"fixed":"3cec135415a89723e2d38e1c8cc5098203355965"},{"fixed":"a41d3d9202e951995cfac6248c565423079c71fa"},{"fixed":"af83e92c329f11139d5eea2b5b7b83c26c3f67e7"},{"fixed":"7a875c09899ba0404844abfd8f0d54cdc481c151"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43430.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.37"},{"fixed":"5.10.253"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.203"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.167"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.130"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.78"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.19"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43430.json"}}],"schema_version":"1.7.5"}