-
CVE-2026-92479
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:09:57
- Zuletzt bearbeitet 17.09.2026 17:17:49
- Erkennungen
scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reporting invalid tags The single-doorbell completion path can call ufshcd_compl_one_cqe() with a NULL CQE. If no command is associated with the completion tag, the warning message dereferences the CQE while reporting the error. Avoid that dereference and include the invalid tag in the warning.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
22089c218037ca7cd50d4fa20e8b5bd746a9b397
Version <
a769095d1d74ebac2b1474c56bbd29bb0b9ed5a7
Status
affected
Version
22089c218037ca7cd50d4fa20e8b5bd746a9b397
Version <
331bda797e6afc143127ce72b1469d73316f49b4
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.19
Status
affected
Version
0
Version <
6.19
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.051 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/a769095d1d74ebac2b1474c56bbd29bb0b9ed5a7
https://git.kernel.org/stable/c/331bda797e6afc143127ce72b1469d73316f49b4