What is CVE-2026-74460?
A vulnerability in the Linux kernel's 'ems_usb' CAN driver fails to properly validate the lengths of CPC messages received over USB, potentially leading to a buffer overflow. A local attacker could exploit this by sending specially crafted packets via a USB device, affecting system stability or security. Affected systems should apply the latest kernel updates.
Azərbaycanca: Linux kernel-də 'ems_usb' CAN sürücüsündə aşkar edilmiş boşluqdur ki, USB vasitəsilə qəbul edilən CPC mesaj uzunluqları düzgün yoxlanılmadığı üçün təhlükəsizlik probleminə yol aça bilər. Bu zəiflik yerli hücumçuya USB qurğu üzərindən xüsusi hazırlanmış paket göndərərək yaddaşda "buffer overflow" yaratmağa imkan verə bilər. Təsirə məruz qalan sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119
FAQ1
In which component of the Linux kernel can CVE-2026-74460 cause a buffer overflow?
This vulnerability was discovered in the 'ems_usb' CAN driver.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.