What is CVE-2026-74458?
This is a vulnerability in the 'kvaser_usb_leaf' driver for Kvaser USB CAN adapters within the Linux kernel. The driver fails to properly validate the length of commands received from the USB buffer, allowing a malformed command shorter than the expected header to be dispatched, potentially leading to undefined behavior. Systems using the affected driver should apply the security patch.
Azərbaycanca: Linux nüvəsində Kvaser USB CAN adapterləri üçün "kvaser_usb_leaf" sürücüsündə aşkar edilmiş zəiflikdir. USB buferindən oxunan komandaların uzunluğu düzgün yoxlanılmadığı üçün, gözləniləndən qısa olan zərərli komandalar işlənərək sistemdə gözlənilməz davranışa səbəb ola bilər. Təsirə məruz qalan sürücüyə malik sistemlərdə təhlükəsizlik yaması tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which Linux kernel driver is affected by CVE-2026-74458?
This vulnerability affects the 'kvaser_usb_leaf' driver for Kvaser USB CAN adapters.
What is the root cause of CVE-2026-74458?
The root cause is the failure to properly validate the length of commands read from the USB buffer, allowing malformed commands shorter than the expected header to be dispatched.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.