Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: iris: gen2: Add sanity check for session stop In iris_kill_session, inst->state is set to IRIS_INST_ERROR and session_close is executed, which will kfree(inst_hfi_gen2->packet). If stop_streaming is called afterward, it will cause a crash. Add a NULL check for inst_hfi_gen2->packet before sendling STOP packet to firmware to fix that.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.15, < 6.18.16 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/72846441c5f6396de9face04e77fa3d28e9915b6Patch
- https://git.kernel.org/stable/c/75992ba43072674fd4767df62a1fe2048565cc60Patch
- https://git.kernel.org/stable/c/9aa8d63d09cfc44d879427cc5ba308012ca4ab8ePatch
FAQ
What is CVE-2026-43217?
CVE-2026-43217 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: media: iris: gen2: Add sanity check for session stop In iris_kill_session, inst->state is set to IRIS_INST_ERROR and session_close...
How severe is CVE-2026-43217?
CVE-2026-43217 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-43217?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.