CVE-2026-43217

In the Linux kernel, the following vulnerability has been resolved: media: iris: gen2: Add sanity check for session stop In iris_kill_session, inst->state is set to IRIS_INST_ERROR and session_close is executed, which will kfree(inst_hfi_gen2->packet). If stop_streaming is called afterward, it will cause a crash. Add a NULL check for inst_hfi_gen2->packet before sendling STOP packet to firmware to fix that.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

11 May 2026, 19:27

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE CWE-401
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux linux Kernel
Linux
References () https://git.kernel.org/stable/c/72846441c5f6396de9face04e77fa3d28e9915b6 - () https://git.kernel.org/stable/c/72846441c5f6396de9face04e77fa3d28e9915b6 - Patch
References () https://git.kernel.org/stable/c/75992ba43072674fd4767df62a1fe2048565cc60 - () https://git.kernel.org/stable/c/75992ba43072674fd4767df62a1fe2048565cc60 - Patch
References () https://git.kernel.org/stable/c/9aa8d63d09cfc44d879427cc5ba308012ca4ab8e - () https://git.kernel.org/stable/c/9aa8d63d09cfc44d879427cc5ba308012ca4ab8e - Patch

06 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 12:16

Updated : 2026-05-11 19:27


NVD link : CVE-2026-43217

Mitre link : CVE-2026-43217

CVE.ORG link : CVE-2026-43217


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-401

Missing Release of Memory after Effective Lifetime