CVE-2026-74460

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
15/08/2026
Last modified:
19/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> can: ems_usb: validate CPC message lengths<br /> <br /> ems_usb_read_bulk_callback() walks CPC messages packed in one USB<br /> receive buffer.<br /> <br /> Check that each declared message fits in the URB payload. Also require the<br /> type-specific payload to cover the fields used by the CAN, state, error and<br /> overrun handlers.

Impact