CVE-2026-74460

Source
https://cve.org/CVERecord?id=CVE-2026-74460
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74460.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74460
Downstream
Published
2026-08-15T12:27:01.274Z
Modified
2026-08-17T03:55:04.202441294Z
Summary
can: ems_usb: validate CPC message lengths
Details

In the Linux kernel, the following vulnerability has been resolved:

can: ems_usb: validate CPC message lengths

emsusbreadbulkcallback() walks CPC messages packed in one USB receive buffer.

Check that each declared message fits in the URB payload. Also require the type-specific payload to cover the fields used by the CAN, state, error and overrun handlers.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74460.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
702171adeed3607ee9603ec30ce081411e36ae42
Fixed
ce8125566b1d0b0f16449407e014addf451804ea
Fixed
0b9090717c7e2184e2c427bbcc752f295116ac1d
Fixed
0b23144c59c126beb4a7761a85a194ae0fe668a5
Fixed
df3ac2a672a5284441f120d486acabdd6740fc2a
Fixed
02925f51377f2a42a6724f00549167499c9302e5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74460.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.32
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74460.json"