staging: greybus: lights: avoid NULL deref

Summary

CVECVE-2026-45978
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-05-27 14:17:14 UTC
Updated2026-05-27 14:48:03 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: staging: greybus: lights: avoid NULL deref gb_lights_light_config() stores channel_count before allocating the channels array. If kcalloc() fails, gb_lights_release() iterates the non-zero count and dereferences light->channels, which is NULL. Allocate channels first and only then publish channels_count so the cleanup path can't walk a NULL pointer.

Risk And Classification

EPSS: 0.000240000 probability, percentile 0.073320000 (date 2026-06-01)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 2870b52bae4c81823ffcb3ed2b0626fb39d64f48 a118724d7641b832fa14323e2733e28ae4834552 git Not specified
CNA Linux Linux affected 2870b52bae4c81823ffcb3ed2b0626fb39d64f48 3cbe694d235d96f628ec7dc6ae4d8bdddb768699 git Not specified
CNA Linux Linux affected 2870b52bae4c81823ffcb3ed2b0626fb39d64f48 ba5022162da63059bae36c4fd84d7031f582c71f git Not specified
CNA Linux Linux affected 2870b52bae4c81823ffcb3ed2b0626fb39d64f48 65f2c608096d766540953d9b170d216aa3b5eb95 git Not specified
CNA Linux Linux affected 2870b52bae4c81823ffcb3ed2b0626fb39d64f48 01b91cb3e748032fd96bbe0043812b426a52f091 git Not specified
CNA Linux Linux affected 2870b52bae4c81823ffcb3ed2b0626fb39d64f48 06162d85f830582da6e9e5fcf9c9504d6da9ae0b git Not specified
CNA Linux Linux affected 2870b52bae4c81823ffcb3ed2b0626fb39d64f48 da46264a7016034a5bbbad034c012ef218b7d0af git Not specified
CNA Linux Linux affected 2870b52bae4c81823ffcb3ed2b0626fb39d64f48 efcffd9a6ad8d190651498d5eda53bfc7cf683a7 git Not specified
CNA Linux Linux affected 4.9 Not specified
CNA Linux Linux unaffected 4.9 semver Not specified
CNA Linux Linux unaffected 5.10.252 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.202 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.165 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.128 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.75 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.14 6.18.* semver Not specified
CNA Linux Linux unaffected 6.19.4 6.19.* semver Not specified
CNA Linux Linux unaffected 7.0 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/a118724d7641b832fa14323e2733e28ae4834552 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/efcffd9a6ad8d190651498d5eda53bfc7cf683a7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/01b91cb3e748032fd96bbe0043812b426a52f091 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/da46264a7016034a5bbbad034c012ef218b7d0af 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ba5022162da63059bae36c4fd84d7031f582c71f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/06162d85f830582da6e9e5fcf9c9504d6da9ae0b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3cbe694d235d96f628ec7dc6ae4d8bdddb768699 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/65f2c608096d766540953d9b170d216aa3b5eb95 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report