SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2026-74457

UNKNOWN · CVSS N/A EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the USB channel control index, which can lead to heap out-of-bounds reads due to insufficient bounds checking on the derived index. This flaw can result in kernel panic when triggered in the IRQ context, potentially causing system instability. Organizations using affected Linux systems, particularly those relying on USB interfaces for communication, should prioritize remediation to mitigate the risk of crashes and service disruptions.

CVE
CVE-2026-74457
Severity
UNKNOWN
CVSS
N/A
EPSS
0.18%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: add bounds check for USB channel index The channel control index ctrl_idx is derived from rx->len which comes directly from a device USB payload. The mask 0x0f allows values 0-15, but the array size of usb_if->dev[] is only 2. Values 2-15 cause heap out-of-bounds read, eventually causing kernel panic in the IRQ context. Add bounds checking for ctrl_idx before the array access in both pcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error().