CVE-2026-89870
- EPSS 0.16%
- Veröffentlicht 16.09.2026 10:31:39
- Zuletzt bearbeitet 16.09.2026 15:18:14
In the Linux kernel, the following vulnerability has been resolved: media: zoran: Avoid freeing a registered video_device twice zoran_init_video_device() installs zoran_vdev_release() as the video_device release callback through zoran_template. Aft...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:31:39
- Zuletzt bearbeitet 16.09.2026 11:16:55
In the Linux kernel, the following vulnerability has been resolved: media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure kthread_run() returns an ERR_PTR on failure, not NULL. When start_streaming() fails, data->kthread_vi...
- EPSS 0.18%
- Veröffentlicht 16.09.2026 10:31:37
- Zuletzt bearbeitet 03.10.2026 11:17:44
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Add timeout while stop_streaming When stop_streaming is called, an infinite loop may occur in some cases. Add a bounded poll of the queue status: loop un...
- EPSS 0.19%
- Veröffentlicht 16.09.2026 10:31:36
- Zuletzt bearbeitet 16.09.2026 11:16:54
In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Resume device before setting EOS flag Setting the EOS flag talks to the firmware via send_firmware_command(), which accesses VPU registers. Both the STRE...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:31:35
- Zuletzt bearbeitet 16.09.2026 11:16:54
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound i2c->length in I2C bsg handlers struct qla_i2c_access carries a 16-bit length field alongside a fixed 64-byte buffer: struct qla_i2c_access { uint16_t devi...
- EPSS 0.21%
- Veröffentlicht 16.09.2026 10:31:35
- Zuletzt bearbeitet 16.09.2026 11:16:54
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers The FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE (256-byte) bounce buffer obtained from dma_pool_allo...
CVE-2026-89863
- EPSS 0.67%
- Veröffentlicht 16.09.2026 10:31:34
- Zuletzt bearbeitet 16.09.2026 15:18:14
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check qla_chk_edif_rx_sa_delete_pending() obtains the SCSI command via GET_CMD_SP(sp) and immediately dereferences cmd->...
- EPSS 0.19%
- Veröffentlicht 16.09.2026 10:31:33
- Zuletzt bearbeitet 16.09.2026 11:16:54
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix BSG job leak on validate flash image error path qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally, telling the FC BSG transport (fc_bsg_host...
CVE-2026-89860
- EPSS 0.34%
- Veröffentlicht 16.09.2026 10:31:32
- Zuletzt bearbeitet 16.09.2026 15:18:13
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Initialize NVMe abort_work once at submission qla_nvme_fcp_abort() and qla_nvme_ls_abort() ran INIT_WORK() on priv->abort_work immediately before schedule_work(). IN...
CVE-2026-89861
- EPSS 0.57%
- Veröffentlicht 16.09.2026 10:31:32
- Zuletzt bearbeitet 16.09.2026 15:18:13
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() In the format 1 path, the virtual port is located on ha->vp_list while holding vport_slock, but the lock is d...