CVE-2026-74455
Published: August 18, 2026Last modified: August 18, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: validate uCAN receive record lengths pcan_usb_fd_decode_buf() walks uCAN records packed in one USB receive buffer. Require each record to contain the fixed header for its type, and verify CAN payload bytes before copying them into the skb.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Vulnerable (6.1.182-r0) |
| 25 LTS | linux-lts | Fixed (6.12.103-r0) | |
| Stream | linux-lts | Vulnerable (6.18.43-r0) |
References
- https://git.kernel.org/stable/c/2427ef427bdd78d862c7c76597bfd9eda88b81f1
- https://git.kernel.org/stable/c/2c8f08f3641a074da40acf05baa5a18ae2739260
- https://git.kernel.org/stable/c/6067c878e38d02a3d5c43497347e143f85c9064a
- https://git.kernel.org/stable/c/93fcab2c6968446316bbb49548848df604d6346f
- https://git.kernel.org/stable/c/d9c115948c3dd5fcc2d0245cec5eb76c098503c8