Bug 2516985 (CVE-2026-74459) - CVE-2026-74459 kernel: can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure
Summary: CVE-2026-74459 kernel: can: etas_es58x: es58x_read_bulk_callback(): fix RX bu...
Keywords:
Status: NEW
Alias: CVE-2026-74459
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-15 12:43 UTC by OSIDB Bzimport
Modified: 2026-09-03 14:29 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-15 12:43:12 UTC
In the Linux kernel, the following vulnerability has been resolved:

can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure

es58x_read_bulk_callback() resubmits the RX URB after processing a received
packet. If the resubmit succeeds, the URB remains anchored and will be
handled by the normal RX path or by teardown.

However, if usb_submit_urb() fails, the callback unanchors the URB and then
returns directly. This skips the existing free_urb path, so the coherent
transfer buffer allocated with usb_alloc_coherent() is not released.

Reuse the existing free_urb path after a resubmit failure so that the RX
coherent buffer is freed before leaving the callback.


Note You need to log in before you can comment on or make changes to this bug.