CVE-2026-1991 | libuvc up to 0.0.7 UVC Descriptor src/device.c uvc_scan_streaming null pointer dereference (Issue 300)
A vulnerability labeled as problematic has been found in libuvc up to 0.0.7. Affected is the function uvc_scan_streaming of the file src/device.c of the component UVC Descriptor Handler. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2026-1991. The attack needs to be approached locally. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.