CVE-2026-74460EPSS p11.4%
CVE-2026-74460CVE-2026-74460
Description
In the Linux kernel, the following vulnerability has been resolved:
can: ems_usb: validate CPC message lengths
ems_usb_read_bulk_callback() walks CPC messages packed in one USB
receive buffer.
Check that each declared message fits in the URB payload. Also require the
type-specific payload to cover the fields used by the CAN, state, error and
overrun handlers.
Scoring
| EPSS | 0.22% probability of exploitation · percentile 11.4% · 2026-10-06T12:00:23Z |
| Last modified | 2026-10-03 |