CVE-2026-31623 | Linux Kernel up to 6.12.82/6.18.23/6.19.13/7.0.0 USB rx_complete frags[] privilege escalation (Nessus ID 310277)
A vulnerability was found in Linux Kernel up to 6.12.82/6.18.23/6.19.13/7.0.0. It has been classified as critical. The impacted element is the function rx_complete of the component USB Handler. The manipulation of the argument frags[] leads to privilege escalation.
This vulnerability is traded as CVE-2026-31623. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is recommended.