SB2026100167 - openEuler 22.03 LTS SP4 update for kernel
Published: October 1, 2026 Updated: October 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 39 vulnerabilities.
1) Use-after-free (CVE-ID: CVE-2026-90037)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to use-after-free in NFSD NFSv4 state management when reaping timed-out close_lru entries concurrently with client expiration. A remote attacker can trigger the use-after-free condition to compromise confidentiality, integrity, and availability.
2) Race condition (CVE-ID: CVE-2026-89897)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a race condition in cec_receive_notify() when handling CEC messages concurrently with follower mode changes or release. A remote attacker can send CEC messages during concurrent follower mode changes or release to compromise confidentiality, integrity, and availability.
3) Use-after-free (CVE-ID: CVE-2026-89899)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a use-after-free race condition in cec_transmit_msg_fh in the CEC subsystem when a blocking transmit wait is interrupted by a signal. A local user can interrupt a blocking transmit wait with a signal to compromise confidentiality, integrity, and availability.
4) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2026-89968)
CWE-ID: CWE-841 - Improper Enforcement of Behavioral Workflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of protocol state in nvmet_tcp_handle_h2c_data_pdu() when processing an unsolicited H2CData PDU before transmitting a requested data transfer (R2T). A remote attacker can send an H2CData PDU for a write command before the R2T is transmitted to cause a denial of service.
The affected subsystem must be configured with allow_any_host.
5) Out-of-bounds write (CVE-ID: CVE-2026-89969)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to an out-of-bounds write in nvmet_tcp_try_recv_pdu() when receiving an over-long NVMe/TCP PDU. A remote attacker can send a duplicate ICReq PDU after header digest negotiation to execute arbitrary code.
The attacker-controlled overflow can overwrite the adjacent header and data digest fields before the duplicate ICReq is rejected.
6) Use-after-free (CVE-ID: CVE-2026-89972)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a missing SRCU grace period in the nvme_alloc_ns() error path when concurrently accessing NVMe multipath namespace paths. A remote attacker can trigger concurrent namespace access during error handling to compromise confidentiality, integrity, and availability.
7) Use-after-free (CVE-ID: CVE-2026-89988)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code, escalate privileges, disclose sensitive information, or cause a denial of service.
The vulnerability exists due to a use-after-free in the kprobe blacklist traversal function __within_kprobe_blacklist() when concurrently checking a kprobe blacklist entry during module unloading. A local user can trigger concurrent blacklist traversal and entry removal to dereference freed memory.
The blacklist traversal can occur in atomic or non-preemptible contexts.
8) Use-after-free (CVE-ID: CVE-2026-90002)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the ftrace set_ftrace_filter and set_ftrace_notrace trace instance files when opening a filter file concurrently with trace instance removal. A local user can race opening a filter file with removal of the trace instance to cause a denial of service.
9) Out-of-bounds read (CVE-ID: CVE-2026-90011)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the iSCSI target login payload buffer when processing a crafted login PDU without a terminating null byte. A remote attacker can send a crafted login PDU to disclose sensitive information and cause a denial of service.
Exploitation is reachable through the CHAP authentication path on a portal configured for CHAP.
10) Use-after-free (CVE-ID: CVE-2026-90036)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the NFSD blocked-lock reaping logic when reaping blocked locks concurrently with client expiration. A remote attacker can cause a client to be freed before nfs4_put_stateowner() dereferences its cl_lock to trigger a use-after-free condition.
11) Out-of-bounds write (CVE-ID: CVE-2026-89894)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a heap-based out-of-bounds write.
The vulnerability exists due to a heap-based buffer overflow in cx231xx VBI buffer handling in cx231xx_do_vbi_copy() when changing video geometry while a VBI stream is running. A local user can allocate a small VBI buffer and change the video width or standard to write past the allocated buffer.
Exploitation requires the device to deliver a field-2 VBI payload.
12) Race condition (CVE-ID: CVE-2026-90091)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the L2CAP socket cleanup handler when concurrent L2CAP socket cleanup and channel teardown occur. A local user can trigger concurrent socket cleanup and channel teardown to cause a denial of service.
13) Use-after-free (CVE-ID: CVE-2026-90392)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in bpf_link_show_fdinfo and bpf_link_get_info_by_fd when reading BPF link information while a linked program is concurrently replaced via bpf_link_update. A local user can concurrently replace a linked program and read BPF link information to trigger a use-after-free condition.
14) Out-of-bounds read (CVE-ID: CVE-2026-90413)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in the iSER login PDU handling code when processing a login PDU whose declared data segment length exceeds the received payload length. A remote attacker can send a crafted login PDU with an oversized declared data segment length to read out-of-bounds memory.
The issue can be triggered before authentication.
15) Out-of-bounds read (CVE-ID: CVE-2026-90414)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause an out-of-bounds read and write heap contents beyond the receive descriptor to backing storage.
The vulnerability exists due to missing validation of the declared data segment length in isert_recv_done() when processing iSER/iSCSI PDUs. A remote user can send a PDU that declares a data segment larger than the received data to cause an out-of-bounds read and write heap contents beyond the receive descriptor to backing storage.
Exploitation requires the full feature phase and negotiated parameters that permit unsolicited or immediate data.
16) Out-of-bounds write (CVE-ID: CVE-2026-93095)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause an out-of-bounds write.
The vulnerability exists due to improper validation of catalog thread records in hfsplus_delete_cat() when rebuilding a catalog key from a corrupted HFS+ image. A local user can supply a corrupted HFS+ image with an oversized thread name length to cause an out-of-bounds write.
17) Improper Check for Unusual or Exceptional Conditions (CVE-ID: CVE-2026-93103)
CWE-ID: CWE-754 - Improper Check for Unusual or Exceptional Conditions
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of an allocation failure in hfi1_free_devdata() when allocating a unit ID for an HFI1 device. A local user can cause unit ID allocation to fail to cause a denial of service.
The issue occurs when cleanup runs before the device has been inserted into the unit table.
18) Use-after-free (CVE-ID: CVE-2026-93104)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a use-after-free.
The vulnerability exists due to returning a dangling pointer in rvt_alloc_device when allocating a port array. A local user can trigger a port-array allocation failure to cause a use-after-free.
19) Race condition (CVE-ID: CVE-2026-93138)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to access incompletely initialized vmlinux BTF data.
The vulnerability exists due to a race condition in bpf_get_btf_vmlinux when concurrently invoking the function during first-time vmlinux BTF parsing. A local user can invoke the affected function concurrently to access incompletely initialized vmlinux BTF data.
The race can occur on weakly ordered architectures when CONFIG_DEBUG_INFO_BTF is enabled.
20) Use-after-free (CVE-ID: CVE-2026-93189)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to failure to quiesce HID input before freeing objects in hid_hw_stop() in the HID core when a driver probe unwinds after HID input has been enabled while HID reports are in flight. A local user can trigger a failed driver initialization while HID reports are being processed to trigger a use-after-free condition.
21) Infinite loop (CVE-ID: CVE-2026-89647)
CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an infinite loop in the Ceph dentry lease reclamation logic when processing valid leases with no cap pressure. A local user can cause ceph_cap_reclaim_work() to repeatedly requeue dentry trimming to cause a denial of service.
22) Use-after-free (CVE-ID: CVE-2026-89478)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access freed memory.
The vulnerability exists due to a use-after-free in the SCTP input queue when processing a DATA chunk after an authenticated ASCONF DEL-IP removes its transport. A remote user can cause a delayed SACK to read the freed transport's state to access freed memory.
23) Use-after-free (CVE-ID: CVE-2026-89479)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access freed memory.
The vulnerability exists due to use-after-free in the SCTP endpoint receive loop when processing a specially crafted SCTP packet containing bundled chunks. A remote attacker can send an SCTP packet that deletes an association before subsequent chunks are processed to access freed memory.
Exploitation requires the packet to be processed from the socket backlog in task context.
24) Race condition (CVE-ID: CVE-2026-89508)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in ucma_set_ib_path() when concurrently handling SET_OPTION requests and context migration. A local user can trigger a race condition to cause a denial of service.
A bound and address-resolved cm_id and an RDMA device are required.
25) Use-after-free (CVE-ID: CVE-2026-89510)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause a use-after-free condition.
The vulnerability exists due to a race condition in the RDMA/cxgb4 device removal and registration work handling when removing an RDMA device while registration work is pending or running. A local privileged user can remove the device while the registration work accesses the device object to cause a use-after-free condition.
26) Race condition (CVE-ID: CVE-2026-89520)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in core scheduling's pick_next_task() when a core scheduling flip occurs while a lock-dropping pick_task() operation is in progress. A local user can trigger concurrent core scheduling flips and task selections to cause a denial of service.
Only systems using core scheduling are affected.
27) Use-after-free (CVE-ID: CVE-2026-89555)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free.
The vulnerability exists due to use-after-free in mpls_multipath_hash when processing MPLS packets with inner IP headers in non-linear data and insufficient tailroom in the linear head. A remote attacker can send a legal Geneve packet through a bareudp/MPLS multipath setup to trigger a use-after-free.
The IPv6 processing path can perform a second pull for the larger header.
28) Integer overflow (CVE-ID: CVE-2026-89559)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform an out-of-bounds write.
The vulnerability exists due to an integer overflow in __nd_label_validate() in the libnvdimm label handler when processing a crafted nslot namespace index value. A local user can supply crafted configuration data through ND_CMD_SET_CONFIG_DATA to perform an out-of-bounds write.
The nslot field may also originate from DIMM label storage.
29) Out-of-bounds write (CVE-ID: CVE-2026-89580)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to write out of bounds.
The vulnerability exists due to a race condition in __bpf_get_stack when a preemptible BPF program accesses a reused per-CPU callchain buffer. A local user can execute a preemptible BPF program to write out of bounds.
The issue can affect non-sleepable raw tracepoint programs on PREEMPT kernels.
30) Use-after-free (CVE-ID: CVE-2026-89636)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a use-after-free.
The vulnerability exists due to use-after-free in the SMB client DFS cache's free_tgts() function when using ce->tgthint after its target entries have been freed. A local user can trigger use of the stale target cache hint to cause a use-after-free.
31) Use-after-free (CVE-ID: CVE-2026-64189)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in ip_set_dump_do() and ip_set_dump_done() in the ipset netfilter subsystem when handling netlink dump operations concurrently with ip_set_list resizing. A local user can trigger concurrent netlink dump and set creation operations to cause a denial of service.
The issue can lead to a general protection fault and kernel panic.
32) Resource exhaustion (CVE-ID: CVE-2026-89648)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in ceph_parse_deleg_inos() when processing MDS create-with-delegation replies. A remote privileged user can send a reply containing excessively large or numerous delegated-inode intervals to cause a denial of service.
Exploitation requires control of a Ceph MDS.
33) Out-of-bounds write (CVE-ID: CVE-2026-89656)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to write beyond the CRUSH workspace.
The vulnerability exists due to improper validation of bucket IDs in the libceph CRUSH map decoder, crush_decode(), when processing a malformed CRUSH map containing a bucket ID that does not match its array slot. A local user can cause the kernel to process such a map and write past a permutation array into memory beyond the CRUSH workspace.
34) Out-of-bounds write (CVE-ID: CVE-2026-89761)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in the AppArmor label vector setup used by aa_label_strn_parse() when parsing label names containing multiple "//&"-separated components. A local user can supply a crafted label name to cause memory corruption.
Every label component must resolve to a loaded profile.
35) Use-after-free (CVE-ID: CVE-2026-89762)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in AppArmor credential handling when replacing stale labels while the task uses overridden credentials. A local user can cause stale-label replacement while using overridden credentials to trigger a use-after-free condition.
36) Use-after-free (CVE-ID: CVE-2026-89763)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in the trusted TPM key type teardown routine when a trusted key operation races with module teardown. A local user can trigger a race between a trusted key operation and module teardown to cause a denial of service.
37) Use-after-free (CVE-ID: CVE-2026-89774)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a use-after-free in the Bluetooth SCO socket connection handling code when handling SCO connection-ready events concurrently with socket closure. A remote attacker can trigger a race between connection setup and socket release to compromise confidentiality, integrity, and availability.
38) Race condition (CVE-ID: CVE-2026-89799)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise confidentiality, integrity, and availability.
The vulnerability exists due to improper synchronization in bpf_get_stackid when accessing the trace entries buffer returned by get_perf_callchain. A local user can invoke bpf_get_stackid to compromise confidentiality, integrity, and availability.
39) Use-after-free (CVE-ID: CVE-2026-89877)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a use-after-free condition.
The vulnerability exists due to a use-after-free in the saa7164_dev_setup() error path when PCI BAR memory-region allocation fails during device setup. A remote attacker can trigger the affected error path to cause a use-after-free condition.
Remediation
Install update from vendor's website.