news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-74455

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.5 Medium
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.18%
Risk score
4.0
Published
2026-08-15
Status
Published

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: validate uCAN receive record lengths pcan_usb_fd_decode_buf() walks uCAN records packed in one USB receive buffer. Require each record to contain the fixed header for its type, and verify CAN payload bytes before copying them into the skb. A flaw was found in the Linux kernel's `peak_usb` Controller Area Network (CAN) driver. This vulnerability arises from insufficient validation of uCAN receive record lengths when processing data from a Universal Serial Bus (USB) receive buffer. A local attacker could potentially exploit this by sending specially crafted uCAN records, leading to memory corruption and potentially a denial of service.

Weaknesses

CWE-805

Coverage 1

Advisories and references