Description
In the Linux kernel, the following vulnerability has been resolved:

media: chips-media: wave5: Fix Null reference while testing fluster

When multi instances are created/destroyed, many interrupts happens
and structures for decoder are removed.
"struct vpu_instance" this structure is shared for all flow in the decoder,
so if the structure is not protected by lock, Null dereference
could happens sometimes.
IRQ Handler was spilt to two phases and Lock was added as well.
Published: 2026-05-06
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux media driver for chips‑media wave5 contains a race condition that can cause a null pointer dereference when multiple instances are created and destroyed concurrently. Because the shared vpu_instance structure is accessed without proper locking, an interrupt handler may return a dereferenced pointer, resulting in a kernel panic. The weakness is a NULL pointer dereference under concurrent access (CWE‑476).

Affected Systems

This flaw affects the Linux kernel's media subsystem in the chips‑media wave5 driver. Any kernel version that includes this driver without the added lock protection is vulnerable. The specific version ranges are not listed, so all kernels shipping the unpatched driver are potentially impacted.

Risk and Exploitability

The CVSS score is 7.8, indicating high severity. The EPSS score is < 1%, suggesting a very low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog, indicating no confirmed public exploitation. Because the flaw requires interaction with the media interface and the ability to spawn multiple decoder instances, it is most likely exploitable only by a local user with access to the driver. The resulting kernel crash would cause a denial of service to the affected system. There is no evidence in the description that this flaw can be leveraged for privilege escalation or remote exploitation.

Generated by OpenCVE AI on May 8, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the lock protection for the chips‑media wave5 driver.
  • If a kernel update cannot be applied immediately, unload or blacklist the chips‑media wave5 driver so it does not load on boot.
  • Restrict access to the media device node by adjusting file permissions or applying SELinux/AppArmor policies to limit which users or processes can interact with the driver.

Generated by OpenCVE AI on May 8, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 08 May 2026 13:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 07 May 2026 12:15:00 +0000


Wed, 06 May 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 06 May 2026 12:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix Null reference while testing fluster When multi instances are created/destroyed, many interrupts happens and structures for decoder are removed. "struct vpu_instance" this structure is shared for all flow in the decoder, so if the structure is not protected by lock, Null dereference could happens sometimes. IRQ Handler was spilt to two phases and Lock was added as well.
Title media: chips-media: wave5: Fix Null reference while testing fluster
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-05-11T22:21:10.712Z

Reserved: 2026-05-01T14:12:55.997Z

Link: CVE-2026-43263

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T12:16:47.257

Modified: 2026-05-08T20:33:12.230

Link: CVE-2026-43263

cve-icon Redhat

Severity :

Publid Date: 2026-05-06T00:00:00Z

Links: CVE-2026-43263 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-08T16:30:12Z

Weaknesses