CVE-2026-74460

Source
https://cve.org/CVERecord?id=CVE-2026-74460
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74460.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74460
Downstream
Published
2026-08-15T12:27:01Z
Modified
2026-08-21T03:30:35Z
Summary
can: ems_usb: validate CPC message lengths
Details

In the Linux kernel, the following vulnerability has been resolved:

can: ems_usb: validate CPC message lengths

ems_usb_read_bulk_callback() walks CPC messages packed in one USB receive buffer.

Check that each declared message fits in the URB payload. Also require the type-specific payload to cover the fields used by the CAN, state, error and overrun handlers.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74460.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
702171adeed3607ee9603ec30ce081411e36ae42
Fixed
bb3cc8da8a2967c0f8e83d148fc6870b19fa32c6
Fixed
db5655287d78f00daf98888a520bb8da4d30126d
Fixed
ce8125566b1d0b0f16449407e014addf451804ea
Fixed
0b9090717c7e2184e2c427bbcc752f295116ac1d
Fixed
0b23144c59c126beb4a7761a85a194ae0fe668a5
Fixed
df3ac2a672a5284441f120d486acabdd6740fc2a
Fixed
02925f51377f2a42a6724f00549167499c9302e5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74460.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.32
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74460.json"