Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74456

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
19/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error<br /> <br /> In peak_usb_start(), each RX URB transfer buffer is allocated with kmalloc()<br /> and the URB is flagged URB_FREE_BUFFER so that the final usb_free_urb() also<br /> frees the transfer buffer.<br /> <br /> If usb_submit_urb() fails, the error path frees the buffer explicitly with<br /> kfree(buf) and then calls usb_free_urb(urb). Because URB_FREE_BUFFER is set,<br /> usb_free_urb() -&gt; urb_destroy() frees the same buffer a second time, a double<br /> free of the transfer buffer.<br /> <br /> BUG: KASAN: double-free in usb_free_urb.part.0+0x91/0xb0<br /> Free of addr ffff8881069ccb80 by task trigger.sh/285<br /> <br /> Call Trace:<br /> kfree+0x113/0x3c0<br /> usb_free_urb.part.0+0x91/0xb0<br /> <br /> Drop the redundant kfree(buf); usb_free_urb() already releases the transfer<br /> buffer. This mirrors commit 03819abbeb11 ("net: usb: lan78xx: Fix double free<br /> issue with interrupt buffer allocation").