CVE-2026-74459: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure es58x_read_bulk_callback() resubmits the RX URB after processing a received packet. If the resubmit succeeds, the URB remains anchored and will be handled by the normal RX path or by teardown. However, if usb_submit_urb() fails, the callback unanchors the URB and then returns directly. This skips the existing free_urb path, so the coherent transfer buffer allocated with usb_alloc_coherent() is not released. Reuse the existing free_urb path after a resubmit failure so that the RX coherent buffer is freed before leaving the callback.

Affected products

  • Linux Linux: from 5.15.203, before 5.15.216 (fixed in 5.15.216); from 6.1.167, before 6.1.183 (fixed in 6.1.183); from 6.6.130, before 6.6.151 (fixed in 6.6.151); from 6.12.77, before 6.12.103 (fixed in 6.12.103); from 6.18.17, before 6.18.44 (fixed in 6.18.44); from 6.19.7, before 6.20 (fixed in 6.20); …

Published 2026-08-15. Last modified 2026-08-19.