Double free in Linux kernel - CVE-2026-74456
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to double free in peak_usb_start() in the peak_usb CAN USB driver when handling a failed URB submission. A local user can trigger the vulnerable error path to cause a denial of service.
The issue occurs because the transfer buffer is freed explicitly after URB submission failure and then freed again when the URB is released.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74456
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/4bb3325075138dd5346b71589a959878b564dc0b
- https://git.kernel.org/stable/c/525640b93d3e5f82f4ebea4730f4e0cf799522ba
- https://git.kernel.org/stable/c/92d0de80ca2223b9c7da78020155b6cb27824cc0
- https://git.kernel.org/stable/c/9b3d5a6d952c38bbcf07f903cbeadefdb56b9bc9
- https://git.kernel.org/stable/c/dfb17bf04a764462000f11258a7c06aa92d1f261