What is CVE-2026-74455?
A vulnerability in the Linux kernel's 'can: peak_usb' driver fails to properly validate uCAN USB receive record lengths. It affects systems using PEAK-System CAN adapters and could lead to memory corruption via crafted USB packets. Applying a kernel update is recommended.
Azərbaycanca: Linux kernel-in 'can: peak_usb' sürücüsündə uCAN USB qəbul buferində yazı uzunluqlarının düzgün yoxlanılmaması aşkarlanıb. Qüsur 'peak_usb' CAN adapterlərindən istifadə edən sistemlərə təsir edir və xüsusi hazırlanmış USB paketləri ilə yaddaş pozuntusuna səbəb ola bilər. Kernel yeniləməsi tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which Linux kernel component is affected by CVE-2026-74455 and what is its root cause?
It affects the 'can: peak_usb' driver. The root cause is the failure to properly validate uCAN USB receive record lengths.
What could happen if CVE-2026-74455 is exploited and how to mitigate it?
It could lead to memory corruption via crafted USB packets. Applying a kernel update is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.