What is CVE-2026-74457?
A vulnerability in the Linux kernel's peak_usb CAN driver lacks proper bounds checking for USB channel index. A malformed index `ctrl_idx` from device payload can cause out-of-bounds write, potentially impacting system stability on affected setups. Update the kernel or apply the relevant patch.
Azərbaycanca: Linux kernel-də tapılmış bu zəiflik peak_usb CAN sürücüsündə USB kanal indeksi üçün yoxlama çatışmazlığıdır. Cihazdan alınan məlumatda səhv indeks `ctrl_idx` massivdən kənar yazmaya səbəb ola bilər, təsirlənmiş sistemlərdə stabilik problemləri yarada bilər. Kernel-i yeniləmək və ya müvafiq yamağı tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787; shared vendor: Linux
FAQ2
Which component of the Linux kernel is affected by CVE-2026-74457?
This vulnerability affects the peak_usb CAN driver in the Linux kernel.
What can a malformed `ctrl_idx` cause in CVE-2026-74457?
A malformed `ctrl_idx` from the device payload can cause an out-of-bounds write, which may lead to system stability issues.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.