Unity Linux 20.1050e Security Update: kernel (UTSA-2026-102086)

medium Nessus Plugin ID 338535

Synopsis

The Unity Linux host is missing one or more security updates.

Description

The Unity Linux 20 host has a package installed that is affected by a vulnerability as referenced in the UTSA-2026-102086 advisory.

In the Linux kernel, the following vulnerability has been resolved:

net: usb: pegasus: validate USB endpoints

The pegasus driver should validate that the device it is probing has the proper number and types of USB endpoints it is expecting before it binds to it. If a malicious device were to not have the same urbs the driver will crash later on when it blindly accesses these endpoints.

Tenable has extracted the preceding description block directly from the Unity Linux security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected kernel package.

See Also

https://cert-portal.siemens.com/productcert/html/ssa-019113.html

https://cert-portal.siemens.com/productcert/html/ssa-082556.html

https://nvd.nist.gov/vuln/detail/CVE-2026-23290

https://security-tracker.debian.org/tracker/CVE-2026-23290

http://www.nessus.org/u?4c31550b

http://www.nessus.org/u?634c2168

http://www.nessus.org/u?6f66a67b

http://www.nessus.org/u?78c15e13

http://www.nessus.org/u?7d1ceca5

http://www.nessus.org/u?88e82cf2

http://www.nessus.org/u?a77fc4a3

http://www.nessus.org/u?b1968dce

http://www.nessus.org/u?b72d86d8

http://www.nessus.org/u?ee33055c

Plugin Details

Severity: Medium

ID: 338535

File Name: unity_linux_UTSA-2026-102086.nasl

Version: 1.1

Type: Local

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.71

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

CVSS Score Source: CVE-2026-23290

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/UOS-Server/release, Host/UOS-Server/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/17/2026

Vulnerability Publication Date: 3/25/2026

Reference Information

CVE: CVE-2026-23290