CVE-2026-74458
In the Linux kernel, the following vulnerability has been resolved:
can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents
The wait and bulk receive paths walk variable-length commands from a USB buffer. A nonzero command shorter than CMD_HEADER_LEN can still be dispatched, and the wait path copies a matching command into a fixed caller-owned struct kvaser_cmd using the device-provided length.
Reject nonzero commands that do not contain the fixed header or that extend beyond the current USB buffer item. In the wait path, also reject a matching command that exceeds the destination before copying it.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee
- https://git.kernel.org/stable/c/185cb1fa38142a3cbf223dd8b3abb24217f330d3
- https://git.kernel.org/stable/c/21f0465fd86d77794aaed8e05f833634f68d178d
- https://git.kernel.org/stable/c/3d0897ec623e422695d70d80ae456f89476c5328
- https://git.kernel.org/stable/c/695aea154bb2d453e6daada1510972fafd075285
- https://git.kernel.org/stable/c/72f96c2942f11a0ae8663adcb3d9ee986e07d4fa
- https://git.kernel.org/stable/c/c00ec53d7dec08134e97071850cc00ef000c5b77
- https://git.kernel.org/stable/c/d9e91672526ffa279709b15490118aea1bdee714
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74458",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"lessThan": "c00ec53d7dec08134e97071850cc00ef000c5b77",
"versionType": "git"
},
{
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"lessThan": "d9e91672526ffa279709b15490118aea1bdee714",
"versionType": "git"
},
{
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"lessThan": "72f96c2942f11a0ae8663adcb3d9ee986e07d4fa",
"versionType": "git"
},
{
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"lessThan": "695aea154bb2d453e6daada1510972fafd075285",
"versionType": "git"
},
{
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"lessThan": "3d0897ec623e422695d70d80ae456f89476c5328",
"versionType": "git"
},
{
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"lessThan": "185cb1fa38142a3cbf223dd8b3abb24217f330d3",
"versionType": "git"
},
{
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"lessThan": "21f0465fd86d77794aaed8e05f833634f68d178d",
"versionType": "git"
},
{
"status": "affected",
"version": "080f40a6fa28dab299da7a652e444b1e2d9231e7",
"lessThan": "0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.265",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.216",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.183",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.151",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T13:17:50.437",
"references": [
{
"url": "https://git.kernel.org/stable/c/0293dd153f9dbc1ddf5dacdccc76b363bce4a8ee",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/185cb1fa38142a3cbf223dd8b3abb24217f330d3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/21f0465fd86d77794aaed8e05f833634f68d178d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3d0897ec623e422695d70d80ae456f89476c5328",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/695aea154bb2d453e6daada1510972fafd075285",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/72f96c2942f11a0ae8663adcb3d9ee986e07d4fa",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c00ec53d7dec08134e97071850cc00ef000c5b77",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d9e91672526ffa279709b15490118aea1bdee714",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents\n\nThe wait and bulk receive paths walk variable-length commands from a\nUSB buffer. A nonzero command shorter than CMD_HEADER_LEN can still be\ndispatched, and the wait path copies a matching command into a fixed\ncaller-owned struct kvaser_cmd using the device-provided length.\n\nReject nonzero commands that do not contain the fixed header or that\nextend beyond the current USB buffer item. In the wait path, also reject\na matching command that exceeds the destination before copying it."
}
],
"lastModified": "2026-08-19T17:21:02.653",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}