CVE-2026-43263

Source
https://cve.org/CVERecord?id=CVE-2026-43263
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43263.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-43263
Downstream
Related
Published
2026-05-06T11:28:50.188Z
Modified
2026-08-12T03:51:34.540653330Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
media: chips-media: wave5: Fix Null reference while testing fluster
Details

In the Linux kernel, the following vulnerability has been resolved:

media: chips-media: wave5: Fix Null reference while testing fluster

When multi instances are created/destroyed, many interrupts happens and structures for decoder are removed. "struct vpu_instance" this structure is shared for all flow in the decoder, so if the structure is not protected by lock, Null dereference could happens sometimes. IRQ Handler was spilt to two phases and Lock was added as well.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43263.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9707a6254a8a6b978bde811a44fe07d86c229d1c
Fixed
ea316b784fe6a61b29131c98cddb24e651b1dcbc
Fixed
d12bcf183ec7da4305d848068d15f18044eaf62a
Fixed
e66ff2b08e4ee1c4d3b84f24818e5bcc178cc3a4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43263.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.8.0
Fixed
6.18.16
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43263.json"