← All Advisories

CVE-2026-74460

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-74460

Key Details

CVECVE-2026-74460
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

can: ems_usb: validate CPC message lengths

ems_usb_read_bulk_callback() walks CPC messages packed in one USB

receive buffer.

Check that each declared message fits in the URB payload. Also require the

type-specific payload to cover the fields used by the CAN, state, error and

overrun handlers. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74460
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74460