๐Ÿ” CVE Alert

CVE-2026-74457

UNKNOWN 0.0

can: peak_usb: add bounds check for USB channel index

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: add bounds check for USB channel index The channel control index ctrl_idx is derived from rx->len which comes directly from a device USB payload. The mask 0x0f allows values 0-15, but the array size of usb_if->dev[] is only 2. Values 2-15 cause heap out-of-bounds read, eventually causing kernel panic in the IRQ context. Add bounds checking for ctrl_idx before the array access in both pcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
d8a199355f8f8a0797c00d98788d7282c9ea38bd < 825c903ca3c98cd0cf0e3de8ab8f2604a5339b3f d8a199355f8f8a0797c00d98788d7282c9ea38bd < f97b7e5e1cdaae15cd95b3a360028c7929664969 d8a199355f8f8a0797c00d98788d7282c9ea38bd < 1acab790b7cecd4e144d1d18bdfe549e282f6b0b d8a199355f8f8a0797c00d98788d7282c9ea38bd < 0149fdb50a30944827acf9600a2cc44de0325a7f d8a199355f8f8a0797c00d98788d7282c9ea38bd < 39132f166ca8ce00ae60d8a9068e06a60943cc4b
Linux / Linux
3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/825c903ca3c98cd0cf0e3de8ab8f2604a5339b3f git.kernel.org: https://git.kernel.org/stable/c/f97b7e5e1cdaae15cd95b3a360028c7929664969 git.kernel.org: https://git.kernel.org/stable/c/1acab790b7cecd4e144d1d18bdfe549e282f6b0b git.kernel.org: https://git.kernel.org/stable/c/0149fdb50a30944827acf9600a2cc44de0325a7f git.kernel.org: https://git.kernel.org/stable/c/39132f166ca8ce00ae60d8a9068e06a60943cc4b