-
CVE-2026-89582
- EPSS 0.17%
- Veröffentlicht 11.09.2026 19:44:48
- Zuletzt bearbeitet 14.09.2026 13:19:12
- Erkennungen
bnx2x: fix double free in bnx2x_init_firmware() error path
In the Linux kernel, the following vulnerability has been resolved: bnx2x: fix double free in bnx2x_init_firmware() error path bnx2x_init_firmware() frees bp->init_ops, bp->init_data and bp->init_ops_offsets in its error path without setting them to NULL. The cleanup function bnx2x_release_firmware() frees the same three pointers unconditionally, so if init_firmware fails and release_firmware is later called (e.g. from __bnx2x_remove or through the function state machine), all three are freed a second time. Set each pointer to NULL after kfree() in the error path so that the subsequent kfree(NULL) in bnx2x_release_firmware() is a safe no-op.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
94a78b79cb5f14c09a42522738d6694c6a1cdd20
Version <
770715784b689749014ce193ef986b706fe8f51c
Status
affected
Version
94a78b79cb5f14c09a42522738d6694c6a1cdd20
Version <
c44e5d6c3189241d5f791bc7b1eddde6b92f802c
Status
affected
Version
94a78b79cb5f14c09a42522738d6694c6a1cdd20
Version <
07d4516e3eb1fcde4a5db29eb556cdb0ebba6265
Status
affected
Version
94a78b79cb5f14c09a42522738d6694c6a1cdd20
Version <
ac280f6872e75df49f3004505bcddff91d9e5362
Status
affected
Version
94a78b79cb5f14c09a42522738d6694c6a1cdd20
Version <
dc98e727b9cfc5e19c796bf893878153f00b222b
Status
affected
Version
94a78b79cb5f14c09a42522738d6694c6a1cdd20
Version <
4d36e38e48340a1ccf92a98c7a22d07a954e5aa3
Status
affected
Version
94a78b79cb5f14c09a42522738d6694c6a1cdd20
Version <
a142c024f07d623e2b6b25943f6c36d4b6b0b4c6
Status
affected
Version
94a78b79cb5f14c09a42522738d6694c6a1cdd20
Version <
d2796ffe38cb4155afe0eab23636295b096c27a5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.31
Status
affected
Version
0
Version <
2.6.31
Status
unaffected
Version <=
5.10.*
Version
5.10.270
Status
unaffected
Version <=
5.15.*
Version
5.15.221
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.4
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/dc98e727b9cfc5e19c796bf893878153f00b222b
https://git.kernel.org/stable/c/4d36e38e48340a1ccf92a98c7a22d07a954e5aa3
https://git.kernel.org/stable/c/a142c024f07d623e2b6b25943f6c36d4b6b0b4c6
https://git.kernel.org/stable/c/d2796ffe38cb4155afe0eab23636295b096c27a5
https://git.kernel.org/stable/c/07d4516e3eb1fcde4a5db29eb556cdb0ebba6265
https://git.kernel.org/stable/c/770715784b689749014ce193ef986b706fe8f51c
https://git.kernel.org/stable/c/ac280f6872e75df49f3004505bcddff91d9e5362
https://git.kernel.org/stable/c/c44e5d6c3189241d5f791bc7b1eddde6b92f802c