SB20260816258 - Out-of-bounds read in Linux kernel usb kvaser_usb driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-74458)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read and buffer overflow risk in kvaser_usb_leaf_wait_cmd() and the bulk receive path when parsing device-provided variable-length commands from a USB buffer. A local attacker can supply a crafted command with an invalid length to cause a denial of service.
The issue affects command handling for nonzero commands that are shorter than the fixed header or that extend beyond the current USB buffer item.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee
- https://git.kernel.org/stable/c/185cb1fa38142a3cbf223dd8b3abb24217f330d3
- https://git.kernel.org/stable/c/21f0465fd86d77794aaed8e05f833634f68d178d
- https://git.kernel.org/stable/c/3d0897ec623e422695d70d80ae456f89476c5328
- https://git.kernel.org/stable/c/695aea154bb2d453e6daada1510972fafd075285