Out-of-bounds read in Linux kernel - CVE-2026-74458

 

Out-of-bounds read in Linux kernel - CVE-2026-74458

Published: August 16, 2026


Vulnerability identifier: #VU143322
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74458
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause a denial of service.

The vulnerability exists due to an out-of-bounds read and buffer overflow risk in kvaser_usb_leaf_wait_cmd() and the bulk receive path when parsing device-provided variable-length commands from a USB buffer. A local attacker can supply a crafted command with an invalid length to cause a denial of service.

The issue affects command handling for nonzero commands that are shorter than the fixed header or that extend beyond the current USB buffer item.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74458

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins