-
CVE-2026-74706
- EPSS 0.2%
- Veröffentlicht 22.08.2026 16:16:45
- Zuletzt bearbeitet 22.08.2026 16:16:45
- CVE-Watchlists
- Unerledigt
bnge: Fix NULL pointer dereference in aux device release
In the Linux kernel, the following vulnerability has been resolved: bnge: Fix NULL pointer dereference in aux device release If allocation of auxr_dev fails during auxiliary device setup, the error path calls auxiliary_device_uninit(), which eventually invokes bnge_aux_dev_release(). The release callback unconditionally dereferences aux_priv->auxr_dev->pdev to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated on this failure path, the dereference results in a NULL pointer exception Retrieve the parent bnge_dev from the auxiliary device's parent instead of auxr_dev, and free auxr_dev only when it was successfully allocated. This allows the release callback to correctly clean up partially initialized auxiliary devices.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
8ac050ec3b1c0dcb5e89cf86fe2ebe0afcc73554
Version <
83ef2f3cab7fe6dd9155cd598dc64be524d963a9
Status
affected
Version
8ac050ec3b1c0dcb5e89cf86fe2ebe0afcc73554
Version <
1cb4298810e27e037d3ca07286ecbb97e89ba58d
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.19
Status
affected
Version
0
Version <
6.19
Status
unaffected
Version <=
7.1.*
Version
7.1.9
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.099 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/1cb4298810e27e037d3ca07286ecbb97e89ba58d
https://git.kernel.org/stable/c/83ef2f3cab7fe6dd9155cd598dc64be524d963a9