{"apiVersion":"1.0","identifier":"CVE-2026-74458","description":"In the Linux kernel, the following vulnerability has been resolved: can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents The wait and bulk receive paths walk variable-length commands from a USB buffer. A nonzero command shorter than CMD_HEADER_LEN can still be dispatched, and the wait path copies a matching command into a fixed caller-owned struct kvaser_cmd using the device-provided length. Reject nonzero commands that do not contain the fixed header or that extend beyond the current USB buffer item. In the wait path, also reject a matching command that exceeds the destination before copying it.","publishedAt":"2026-08-15T13:17:50","lastModifiedAt":"2026-08-19T17:21:02","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74458","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00177,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74458","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74458","en":"https://www.redsauce.net/en/cves/CVE-2026-74458","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74458","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74458","de":"https://www.redsauce.net/de/cves/CVE-2026-74458","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74458","el":"https://www.redsauce.net/el/cves/CVE-2026-74458"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74458"}}