CVE-2026-74455

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/08/2026
Last modified:
19/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> can: peak_usb: validate uCAN receive record lengths<br /> <br /> pcan_usb_fd_decode_buf() walks uCAN records packed in one USB<br /> receive buffer.<br /> <br /> Require each record to contain the fixed header for its type, and verify<br /> CAN payload bytes before copying them into the skb.

Impact