PatchSiren cyber security CVE debrief
CVE-2026-74459 Linux CVE debrief
A vulnerability in the Linux kernel has been resolved, related to the can: etas_es58x driver. The issue occurs in the es58x_read_bulk_callback() function, where a RX buffer leak can happen on URB resubmit failure. This can cause memory leaks and potentially lead to denial-of-service (DoS) attacks. Linux kernel developers and maintainers should review the patch and apply it to affected systems. The patch fixes the issue by reusing the existing free_urb path after a resubmit failure, ensuring that the RX coherent buffer is freed.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers and maintainers, Linux system administrators, and users of the etas_es58x driver should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing and applying the patch, monitoring Linux kernel updates for potential related vulnerabilities, and inventorying Linux systems for etas_es58x driver usage. Additionally, security teams and vulnerability management teams should prioritize patching affected systems to prevent potential attacks. Affected operators should also review compensating controls for exposed systems while remediation is scheduled and verified. Those impacted should track exceptions, retest remediated assets, and close the item only after evidence is documented. Linux distributions and vendors may also need to assess and address this vulnerability in their products and provide guidance to their customers. Security researchers and penetration testers may also be interested in this vulnerability as it relates to the Linux kernel and IoT device security. Finally, Linux users and organizations that rely on the Linux kernel should be aware of the potential risks and take steps to mitigate them. This may involve reviewing system logs for signs of exploitation and implementing additional security controls to detect and prevent attacks. Those who use or support Linux systems should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets that need extra review should be checked. Exceptions should be tracked, remediated assets should be retested, and the item should be closed only after evidence is documented. Those impacted should also consider reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Those who manage Linux systems should also consider checking for and applying any available back
Technical summary
The es58x_read_bulk_callback() function in the Linux kernel can: etas_es58x driver has a vulnerability that can cause a RX buffer leak on URB resubmit failure. This happens when the usb_submit_urb() function fails, causing the URB to be unanchored and the coherent transfer buffer to not be released. The issue has been resolved by reusing the existing free_urb path after a resubmit failure, ensuring that the RX coherent buffer is freed before leaving the callback. This fix prevents potential memory leaks and denial-of-service (DoS) attacks.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the patch for the Linux kernel can: etas_es58x driver
- Monitor Linux kernel updates for potential related vulnerabilities
- Inventory Linux systems for etas_es58x driver usage
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability is caused by the es58x_read_bulk_callback() function not properly handling URB resubmit failures, leading to a RX buffer leak. The issue has been resolved by reusing the existing free_urb path after a resubmit failure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74459 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74459
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74459 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74459
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0ef136ba052101243ba117a1aca6f4a4c3a81142
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/19c6c8c6cd5dd14fab5fcd744584812a57cbb78d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7a0cf2b2497c757c3cb1286eddf2986abb0d387b
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b85e5c310382803d27adf6fe6554d4208bc8951c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c311f17c261fd375ddf5755f2ebe1f022c19c5b0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.