Debian

Debian 12 (bookworm)

14804 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:35
  • Zuletzt bearbeitet 16.09.2026 11:16:54

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound i2c->length in I2C bsg handlers struct qla_i2c_access carries a 16-bit length field alongside a fixed 64-byte buffer: struct qla_i2c_access { uint16_t devi...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:35
  • Zuletzt bearbeitet 16.09.2026 11:16:54

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers The FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE (256-byte) bounce buffer obtained from dma_pool_allo...

  • EPSS 0.67%
  • Veröffentlicht 16.09.2026 10:31:34
  • Zuletzt bearbeitet 16.09.2026 15:18:14

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check qla_chk_edif_rx_sa_delete_pending() obtains the SCSI command via GET_CMD_SP(sp) and immediately dereferences cmd->...

  • EPSS 0.19%
  • Veröffentlicht 16.09.2026 10:31:33
  • Zuletzt bearbeitet 16.09.2026 11:16:54

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix BSG job leak on validate flash image error path qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally, telling the FC BSG transport (fc_bsg_host...

  • EPSS 0.34%
  • Veröffentlicht 16.09.2026 10:31:32
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Initialize NVMe abort_work once at submission qla_nvme_fcp_abort() and qla_nvme_ls_abort() ran INIT_WORK() on priv->abort_work immediately before schedule_work(). IN...

  • EPSS 0.57%
  • Veröffentlicht 16.09.2026 10:31:32
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() In the format 1 path, the virtual port is located on ha->vp_list while holding vport_slock, but the lock is d...

  • EPSS 0.19%
  • Veröffentlicht 16.09.2026 10:31:31
  • Zuletzt bearbeitet 03.10.2026 11:17:44

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak qla2x00_do_dport_diagnostics() allocates the qla_dport_diag response buffer with kmalloc_obj() (non-zeroing) and, on...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:30
  • Zuletzt bearbeitet 16.09.2026 11:16:53

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() qla2x00_update_fru_versions() copies the user-supplied BSG request into a fixed 256-byte stack buffer (bsg[DMA_POO...

  • EPSS 0.18%
  • Veröffentlicht 16.09.2026 10:31:29
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and ha->max_qpairs are u8. Deriving the queue ...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:28
  • Zuletzt bearbeitet 16.09.2026 11:16:53

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in reset handler The "update cache versions without reset" sysfs reset operation (0x20261) calls get_flash_version(), which reads hardwa...