Debian

Debian 12 (bookworm)

14804 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:27
  • Zuletzt bearbeitet 16.09.2026 11:16:53

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27x...

  • EPSS 0.16%
  • Veröffentlicht 16.09.2026 10:31:27
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix cs84xx use-after-free on host teardown qla84xx_put_chip() drops the last reference to ha->cs84xx and frees it via __qla84xx_chip_release() without clearing ha->c...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:26
  • Zuletzt bearbeitet 16.09.2026 11:16:52

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() The mbx_cmd_t is allocated on the stack but left uninitialized. qla2x00_mailbox_command() has several early-retur...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:25
  • Zuletzt bearbeitet 16.09.2026 11:16:52

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debugfs qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer, so a successful parse would dereference NULL and oops. ...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:24
  • Zuletzt bearbeitet 16.09.2026 11:16:52

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Don't query firmware state while chip is down qla2x00_fw_state_show() initializes rval to QLA_FUNCTION_FAILED and jumps to the out: label when the chip is down or EE...

  • EPSS 0.35%
  • Veröffentlicht 16.09.2026 10:31:23
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path qla2x00_status_entry() filters out non-TYPE_SRB entries and the SRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then fa...

  • EPSS 0.51%
  • Veröffentlicht 16.09.2026 10:31:22
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Quiesce response IRQ before freeing request queue qla2xxx_delete_qpair() deletes the request queue before the response queue. qla25xx_delete_req_que() frees the requ...

  • EPSS 0.68%
  • Veröffentlicht 16.09.2026 10:31:21
  • Zuletzt bearbeitet 16.09.2026 15:18:12

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOCB timeout qla2x00_async_iocb_timeout() tries to abort a timed-out async IOCB. When qla24xx_async_abort_cmd() fails, both the SRB_...

  • EPSS 0.7%
  • Veröffentlicht 16.09.2026 10:31:20
  • Zuletzt bearbeitet 16.09.2026 15:18:12

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path advances sense_data and shrinks par_sense_len by rsp_info_len: if (...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:19
  • Zuletzt bearbeitet 16.09.2026 11:16:51

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() qla2x00_error_entry() reads ha->req_q_map[que] twice: once for the NULL check and again when assigning it to req...