Out-of-bounds read in Linux kernel - CVE-2026-74458
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read and buffer overflow risk in kvaser_usb_leaf_wait_cmd() and the bulk receive path when parsing device-provided variable-length commands from a USB buffer. A local attacker can supply a crafted command with an invalid length to cause a denial of service.
The issue affects command handling for nonzero commands that are shorter than the fixed header or that extend beyond the current USB buffer item.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74458
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee
- https://git.kernel.org/stable/c/185cb1fa38142a3cbf223dd8b3abb24217f330d3
- https://git.kernel.org/stable/c/21f0465fd86d77794aaed8e05f833634f68d178d
- https://git.kernel.org/stable/c/3d0897ec623e422695d70d80ae456f89476c5328
- https://git.kernel.org/stable/c/695aea154bb2d453e6daada1510972fafd075285