CVE-2026-23334Incorrect Calculation of Buffer Size in Linux

Severity
7.8HIGH
No vector
EPSS
0.0%
top 93.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 25

Description

In the Linux kernel, the following vulnerability has been resolved: can: usb: f81604: handle short interrupt urb messages properly If an interrupt urb is received that is not the correct length, properly detect it and don't attempt to treat the data as valid.

Affected Packages5 packages

Linuxlinux/linux_kernel6.5.06.6.130+3
Debianlinux/linux_kernel< 6.19.8-1
CVEListV5linux/linux88da17436973e463bed59bea79771fb03a21555e9b740ff5bc649575a5e14ca8ee54e3dd5010aaf0+5
debiandebian/linux< linux 6.19.8-1 (forky)

🔴Vulnerability Details

3
OSV
CVE-2026-23334: In the Linux kernel, the following vulnerability has been resolved: can: usb: f81604: handle short interrupt urb messages properly If an interrupt urb2026-03-25
OSV
can: usb: f81604: handle short interrupt urb messages properly2026-03-25
GHSA
GHSA-2x56-x8gq-8cv3: In the Linux kernel, the following vulnerability has been resolved: can: usb: f81604: handle short interrupt urb messages properly If an interrupt u2026-03-25

📋Vendor Advisories

3
Red Hat
kernel: can: usb: f81604: handle short interrupt urb messages properly2026-03-25
Microsoft
can: usb: f81604: handle short interrupt urb messages properly2026-03-10
Debian
CVE-2026-23334: linux - In the Linux kernel, the following vulnerability has been resolved: can: usb: f...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23334 Impact, Exploitability, and Mitigation Steps | Wiz