SB20260816256 - Double free in Linux kernel usb peak_usb driver



SB20260816256 - Double free in Linux kernel usb peak_usb driver

Published: August 16, 2026

Security Bulletin ID SB20260816256
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Double free (CVE-ID: CVE-2026-74456)

CWE-ID: CWE-415 - Double Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to double free in peak_usb_start() in the peak_usb CAN USB driver when handling a failed URB submission. A local user can trigger the vulnerable error path to cause a denial of service.

The issue occurs because the transfer buffer is freed explicitly after URB submission failure and then freed again when the URB is released.


Remediation

Install update from vendor's website.