CVE-2026-74455
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/08/2026
Last modified:
19/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
can: peak_usb: validate uCAN receive record lengths<br />
<br />
pcan_usb_fd_decode_buf() walks uCAN records packed in one USB<br />
receive buffer.<br />
<br />
Require each record to contain the fixed header for its type, and verify<br />
CAN payload bytes before copying them into the skb.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2427ef427bdd78d862c7c76597bfd9eda88b81f1
- https://git.kernel.org/stable/c/276d989cd2dd88e2b7ab2c96fd10c86836b12781
- https://git.kernel.org/stable/c/2c8f08f3641a074da40acf05baa5a18ae2739260
- https://git.kernel.org/stable/c/6067c878e38d02a3d5c43497347e143f85c9064a
- https://git.kernel.org/stable/c/89c92a8052698dbbd3652a77c04d02bbd74a3275
- https://git.kernel.org/stable/c/93fcab2c6968446316bbb49548848df604d6346f
- https://git.kernel.org/stable/c/bf9d787b7e1ef59be19b35abca08194772deb97e
- https://git.kernel.org/stable/c/d9c115948c3dd5fcc2d0245cec5eb76c098503c8


