Out-of-bounds read in Linux kernel - CVE-2026-74460
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in ems_usb_read_bulk_callback() in the ems_usb CAN USB driver when processing crafted CPC messages in a USB receive buffer. A local attacker can supply a crafted CPC message with an invalid length to cause a denial of service.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74460
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/02925f51377f2a42a6724f00549167499c9302e5
- https://git.kernel.org/stable/c/0b23144c59c126beb4a7761a85a194ae0fe668a5
- https://git.kernel.org/stable/c/0b9090717c7e2184e2c427bbcc752f295116ac1d
- https://git.kernel.org/stable/c/ce8125566b1d0b0f16449407e014addf451804ea
- https://git.kernel.org/stable/c/df3ac2a672a5284441f120d486acabdd6740fc2a