---
id: CVE-2026-74460
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  can: ems_usb: validate CPC message lengths

  ems_usb_read_bulk_callback() walks CPC messages packed in one USB
  receive buffer.

  Check that each declared message fits in …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  can: ems_usb: validate CPC message lengths

  ems_usb_read_bulk_callback() walks CPC messages packed in one USB
  receive buffer.

  Check that each declared message fits in …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 702171adeed3607ee9603ec30ce081411e36ae42 <
    1c380a332e342b7d58c86c4f556cb0823b16a9b8
  - >-
    Linux >= 702171adeed3607ee9603ec30ce081411e36ae42 <
    bb3cc8da8a2967c0f8e83d148fc6870b19fa32c6
  - >-
    Linux >= 702171adeed3607ee9603ec30ce081411e36ae42 <
    db5655287d78f00daf98888a520bb8da4d30126d
  - >-
    Linux >= 702171adeed3607ee9603ec30ce081411e36ae42 <
    ce8125566b1d0b0f16449407e014addf451804ea
  - >-
    Linux >= 702171adeed3607ee9603ec30ce081411e36ae42 <
    0b9090717c7e2184e2c427bbcc752f295116ac1d
  - >-
    Linux >= 702171adeed3607ee9603ec30ce081411e36ae42 <
    0b23144c59c126beb4a7761a85a194ae0fe668a5
  - >-
    Linux >= 702171adeed3607ee9603ec30ce081411e36ae42 <
    df3ac2a672a5284441f120d486acabdd6740fc2a
  - >-
    Linux >= 702171adeed3607ee9603ec30ce081411e36ae42 <
    02925f51377f2a42a6724f00549167499c9302e5
  - Linux 2.6.32
published: '2026-08-15'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:38.843'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74460'
references:
  - url: 'https://git.kernel.org/stable/c/02925f51377f2a42a6724f00549167499c9302e5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/0b23144c59c126beb4a7761a85a194ae0fe668a5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/0b9090717c7e2184e2c427bbcc752f295116ac1d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1c380a332e342b7d58c86c4f556cb0823b16a9b8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bb3cc8da8a2967c0f8e83d148fc6870b19fa32c6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ce8125566b1d0b0f16449407e014addf451804ea'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/db5655287d78f00daf98888a520bb8da4d30126d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/df3ac2a672a5284441f120d486acabdd6740fc2a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00215
epssPercentile: 0.10754
ingestedAt: '2026-10-03T11:43:42.119Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

can: ems_usb: validate CPC message lengths

ems_usb_read_bulk_callback() walks CPC messages packed in one USB
receive buffer.

Check that each declared message fits in the URB payload. Also require the
type-specific payload to cover the fields used by the CAN, state, error and
overrun handlers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
