
We have just added an important vulnerability affecting Linux Kernel (CVE-2026-23078) https://vuldb.com/?id.344335
Post summary
The text announces that CVE-2026-23078, a Linux Kernel vulnerability, has been added to a vulnerability database.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Fix buffer overflow in config retrieval The scarlett2_usb_get_config() function has a logic error in the endianness conversion code that can cause buffer overflows when count > 1. The code checks `if (size == 2)` where `size` is the total buffer size in bytes, then loops `count` times treating each element as u16 (2 bytes). This causes the loop to access `count * 2` bytes when the buffer only has `size` bytes allocated. Fix by checking the element size (config_item->size) instead of the total buffer size. This ensures the endianness conversion matches the actual element type.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

We have just added an important vulnerability affecting Linux Kernel (CVE-2026-23078) https://vuldb.com/?id.344335
Post summary
The text announces that CVE-2026-23078, a Linux Kernel vulnerability, has been added to a vulnerability database.
7 of 7 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| OS | linux | linux_kernel | - | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |
| OS | linux | linux_kernel | 6.19 | - | - |