Vulnerabilities
- CVSS
- 5.5 Medium
- Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- EPSS
- 0.18%
- Risk score
- 4.0
- Published
- 2026-08-15
- Status
- Published
In the Linux kernel, the following vulnerability has been resolved:
can: peak_usb: validate uCAN receive record lengths
pcan_usb_fd_decode_buf() walks uCAN records packed in one USB
receive buffer.
Require each record to contain the fixed header for its type, and verify
CAN payload bytes before copying them into the skb.
A flaw was found in the Linux kernel's `peak_usb` Controller Area Network (CAN) driver. This vulnerability arises from insufficient validation of uCAN receive record lengths when processing data from a Universal Serial Bus (USB) receive buffer. A local attacker could potentially exploit this by sending specially crafted uCAN records, leading to memory corruption and potentially a denial of service.
Coverage 1
threat-intel
Multiple vulnerabilities have been discovered in the Linux kernel of Debian. These vulnerabilities allow for privilege escalation, data compromise, and denial of service. The affected Debian versions are prior to 6.12.10…
Advisories and references