In the Linux kernel, the following vulnerability has been resolved:
media: iris: gen2: Add sanity check for session stop
In iris_kill_session, inst->state is set to IRIS_INST_ERROR and
session_close is executed, which will kfree(inst_hfi_gen2->packet).
If stop_streaming is called afterward, it will cause a crash.
Add a NULL check for inst_hfi_gen2->packet before sendling STOP packet
to firmware to fix that.
References
Configurations
Configuration 1 (hide)
|
History
11 May 2026, 19:27
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | |
| CWE | CWE-401 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| First Time |
Linux linux Kernel
Linux |
|
| References | () https://git.kernel.org/stable/c/72846441c5f6396de9face04e77fa3d28e9915b6 - Patch | |
| References | () https://git.kernel.org/stable/c/75992ba43072674fd4767df62a1fe2048565cc60 - Patch | |
| References | () https://git.kernel.org/stable/c/9aa8d63d09cfc44d879427cc5ba308012ca4ab8e - Patch |
06 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-06 12:16
Updated : 2026-05-11 19:27
NVD link : CVE-2026-43217
Mitre link : CVE-2026-43217
CVE.ORG link : CVE-2026-43217
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
