CVE-2026-89582
In the Linux kernel, the following vulnerability has been resolved: bnx2x: fix double free in bnx2x_init_firmware() error path bnx2x_init_firmware() frees bp->init_ops, bp->init_data and bp->init_ops_offsets in its error path without setting them to NULL. The cleanup function bnx2x_release_firmware() frees the same three pointers unconditionally, so if init_firmware fails and release_firmware is later called (e.g. from __bnx2x_remove or through the function state machine), all three are freed a second time. Set each pointer to NULL after kfree() in the error path so that the subsequent kfree(NULL) in bnx2x_release_firmware() is a safe no-op.
What this means for your business
- FIRST's prediction model gives it a 0.2% chance of attack attempts being seen in the next 30 days, ranking above 7% of all known flaws.
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- Not yet scored
- Assigned by
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Dates
- Published
- 2026-09-11
- Last modified
- 2026-09-14
- Sources
- NVD
References
- https://git.kernel.org/stable/c/07d4516e3eb1fcde4a5db29eb556cdb0ebba6265
- https://git.kernel.org/stable/c/4d36e38e48340a1ccf92a98c7a22d07a954e5aa3
- https://git.kernel.org/stable/c/770715784b689749014ce193ef986b706fe8f51c
- https://git.kernel.org/stable/c/a142c024f07d623e2b6b25943f6c36d4b6b0b4c6
- https://git.kernel.org/stable/c/ac280f6872e75df49f3004505bcddff91d9e5362
- https://git.kernel.org/stable/c/c44e5d6c3189241d5f791bc7b1eddde6b92f802c
- https://git.kernel.org/stable/c/d2796ffe38cb4155afe0eab23636295b096c27a5
- https://git.kernel.org/stable/c/dc98e727b9cfc5e19c796bf893878153f00b222b