In the Linux kernel, the following vulnerability has been resolved:
media: nxp: imx8-isi: Check whether crossbar pad is non-NULL before access
When translating source to sink streams in the crossbar subdev, the driver tries to locate the remote subdev connected to the sink pad. The remote pad may be NULL, if userspace tries to enable a stream that ends at an unconnected crossbar sink. When that occurs, the driver dereferences the NULL pad, leading to a crash.
Prevent the crash by checking if the pad is NULL before using it, and return an error if it is.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-awsUpgrade linux-image-6.8.0-35-lowlatencyUpgrade linux-image-6.8.0-1006-oemUpgrade linux-image-6.8.0-35-lowlatency-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-gkeUpgrade linux-image-gcpUpgrade linux-image-oracleUpgrade linux-image-virtualUpgrade linux-image-6.8.0-1004-gkeUpgrade linux-image-oem-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-1008-azure-fdeUpgrade linux-image-6.8.0-1009-awsUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-lowlatency-64kUpgrade linux-image-6.8.0-1006-oracleUpgrade linux-image-6.8.0-35-genericUpgrade linux-image-ibmUpgrade linux-image-generic-64kUpgrade linux-image-raspiUpgrade linux-image-6.8.0-35-generic-64kUpgrade linux-image-azure-fdeUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-6.8.0-1006-oracle-64kUpgrade linux-image-generic-lpaeUpgrade linux-image-azureUpgrade linux-image-kvmUpgrade linux-image-6.8.0-1006-ibmUpgrade linux-image-6.8.0-1008-azureUpgrade linux-image-genericUpgrade linux-image-lowlatencyUpgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-1005-raspiUpgrade linux-image-6.8.0-1008-gcp | Jul 1, 2024 | May 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub