CVE-2026-74457 PUBLISHED

can: peak_usb: add bounds check for USB channel index

Assigner: Linux
Reserved: 15.08.2026 Published: 15.08.2026 Updated: 15.08.2026

In the Linux kernel, the following vulnerability has been resolved:

can: peak_usb: add bounds check for USB channel index

The channel control index ctrl_idx is derived from rx->len which comes directly from a device USB payload. The mask 0x0f allows values 0-15, but the array size of usb_if->dev[] is only 2. Values 2-15 cause heap out-of-bounds read, eventually causing kernel panic in the IRQ context.

Add bounds checking for ctrl_idx before the array access in both pcan_usb_pro_handle_canmsg() and pcan_usb_pro_handle_error().

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d8a199355f8f8a0797c00d98788d7282c9ea38bd to 825c903ca3c98cd0cf0e3de8ab8f2604a5339b3f (excl.)
  • affected from d8a199355f8f8a0797c00d98788d7282c9ea38bd to f97b7e5e1cdaae15cd95b3a360028c7929664969 (excl.)
  • affected from d8a199355f8f8a0797c00d98788d7282c9ea38bd to 1acab790b7cecd4e144d1d18bdfe549e282f6b0b (excl.)
  • affected from d8a199355f8f8a0797c00d98788d7282c9ea38bd to 0149fdb50a30944827acf9600a2cc44de0325a7f (excl.)
  • affected from d8a199355f8f8a0797c00d98788d7282c9ea38bd to 39132f166ca8ce00ae60d8a9068e06a60943cc4b (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.4 is affected
  • unaffected from 0 to 3.4 (excl.)
  • unaffected from 6.6.151 to 6.6.* (incl.)
  • unaffected from 6.12.103 to 6.12.* (incl.)
  • unaffected from 6.18.44 to 6.18.* (incl.)
  • unaffected from 7.1.8 to 7.1.* (incl.)
  • unaffected from 7.2-rc6 to * (incl.)

References