Debian

Debian 13 (trixie)

17739 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 16.09.2026 10:31:31
  • Zuletzt bearbeitet 03.10.2026 11:17:44

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak qla2x00_do_dport_diagnostics() allocates the qla_dport_diag response buffer with kmalloc_obj() (non-zeroing) and, on...

  • EPSS 0.62%
  • Veröffentlicht 16.09.2026 10:31:30
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject qla_nvme_ls_reject_iocb() allocates from and advances the request ring through __qla2x00_alloc_iocbs() (which assumes the...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:30
  • Zuletzt bearbeitet 16.09.2026 11:16:53

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() qla2x00_update_fru_versions() copies the user-supplied BSG request into a fixed 256-byte stack buffer (bsg[DMA_POO...

  • EPSS 0.18%
  • Veröffentlicht 16.09.2026 10:31:29
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and ha->max_qpairs are u8. Deriving the queue ...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:28
  • Zuletzt bearbeitet 16.09.2026 11:16:53

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in reset handler The "update cache versions without reset" sysfs reset operation (0x20261) calls get_flash_version(), which reads hardwa...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:27
  • Zuletzt bearbeitet 16.09.2026 11:16:53

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump qla2x00_free_fce_trace() freed and cleared ha->fce while holding only fce_mutex. The firmware-dump consumers qla27x...

  • EPSS 0.16%
  • Veröffentlicht 16.09.2026 10:31:27
  • Zuletzt bearbeitet 16.09.2026 15:18:13

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix cs84xx use-after-free on host teardown qla84xx_put_chip() drops the last reference to ha->cs84xx and frees it via __qla84xx_chip_release() without clearing ha->c...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:26
  • Zuletzt bearbeitet 16.09.2026 11:16:52

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() The mbx_cmd_t is allocated on the stack but left uninitialized. qla2x00_mailbox_command() has several early-retur...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:25
  • Zuletzt bearbeitet 16.09.2026 11:16:52

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debugfs qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer, so a successful parse would dereference NULL and oops. ...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2026 10:31:24
  • Zuletzt bearbeitet 16.09.2026 11:16:52

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Don't query firmware state while chip is down qla2x00_fw_state_show() initializes rval to QLA_FUNCTION_FAILED and jumps to the out: label when the chip is down or EE...