VulnerabilityReceived
CVE-2026-74455
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: validate uCAN receive record lengths pcan_usb_fd_decode_buf() walks uCAN records packed in one USB receive buffer.
UnscoredEPSS 0.18%
Does this matter?
Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.
Description
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: validate uCAN receive record lengths pcan_usb_fd_decode_buf() walks uCAN records packed in one USB receive buffer. Require each record to contain the fixed header for its type, and verify CAN payload bytes before copying them into the skb.
- CVSS
- Not yet scored
- EPSS
- 0.18% probability · 7th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/2427ef427bdd78d862c7c76597bfd9eda88b81f1
- https://git.kernel.org/stable/c/276d989cd2dd88e2b7ab2c96fd10c86836b12781
- https://git.kernel.org/stable/c/2c8f08f3641a074da40acf05baa5a18ae2739260
- https://git.kernel.org/stable/c/6067c878e38d02a3d5c43497347e143f85c9064a
- https://git.kernel.org/stable/c/89c92a8052698dbbd3652a77c04d02bbd74a3275
- https://git.kernel.org/stable/c/93fcab2c6968446316bbb49548848df604d6346f
- https://git.kernel.org/stable/c/bf9d787b7e1ef59be19b35abca08194772deb97e
- https://git.kernel.org/stable/c/d9c115948c3dd5fcc2d0245cec5eb76c098503c8
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.