What is CVE-2026-74456?
In the Linux kernel's peak_usb CAN driver, a vulnerability was found where a double free of the transfer buffer occurs on URB submit error. This could be exploited by a local attacker with physical access to cause a denial of service or potentially escalate privileges. It is recommended to update the kernel to the latest patched version.
Azərbaycanca: Linux kernel-də peak_usb CAN sürücüsündə aşkar edilmiş bu boşluq, URB göndərişi uğursuz olduqda transfer buferinin iki dəfə azad edilməsinə (double free) səbəb olur. Bu zəiflik, xüsusilə fiziki giriş imkanı olan yerli təcavüzkar tərəfindən xidmətdən imtina (DoS) və ya potensial olaraq imtiyaz yüksəltmə üçün istismar edilə bilər. Təsirə məruz qalan sistemlərdə kernel-i ən son yamaqlanmış versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Where is the CVE-2026-74456 vulnerability located and which driver does it affect?
This vulnerability was found in the Linux kernel's peak_usb CAN driver.
What is the technical consequence when a URB submit error occurs?
A double free of the transfer buffer occurs on URB submit error.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.