Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3451 articles · 142163 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-43312EXPLOITEDPATCHED
linux · linux kernel

media: i2c: ov5647: Initialize subdev before controls

Description

A vulnerability marked as critical has been reported in Linux Kernel up to 6.19.5. This issue affects the function ov5647_init_controls. The manipulation leads to improper initialization. This vulnerability is referenced as CVE-2026-43312. The attack needs to be initiated within the local network. No exploit is available. It is suggested to upgrade the affected component.

Affected Products

VendorProductVersions
linuxlinux kernel4974c2f19fd810ec9a4e534bfc69e176256b7a03, 4974c2f19fd810ec9a4e534bfc69e176256b7a03, 4974c2f19fd810ec9a4e534bfc69e176256b7a03, 4974c2f19fd810ec9a4e534bfc69e176256b7a03, 4974c2f19fd810ec9a4e534bfc69e176256b7a03, 4974c2f19fd810ec9a4e534bfc69e176256b7a03, 4974c2f19fd810ec9a4e534bfc69e176256b7a03, 5.12, 6.19.5

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourceopen source linux kernelcert_advisory90%

References

  • https://git.kernel.org/stable/c/f2a1998bc0053ebfe137f65081ed13afd9f34502
  • https://git.kernel.org/stable/c/59e372aa4cf60e2500eba7f978acdcb18bb49032
  • https://git.kernel.org/stable/c/cabd025182cfed4a19b3aab57493e312d681e398
  • https://git.kernel.org/stable/c/2dedda97a64e7735844609c6c77c0dd953d73833
  • https://git.kernel.org/stable/c/8ecb21c20387cc0c8aa00489a21ccc69f6b0f5d1
  • https://git.kernel.org/stable/c/fb69e4842f5b463ff5f121d2ac7746014e3477ea
  • https://git.kernel.org/stable/c/eee13cbccacb6d0a3120c126b8544030905b069d

Related News (3 articles)

Tier B
BSI Advisories8h ago
[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-43312 | Linux Kernel up to 6.19.5 ov5647_init_controls initialization
→ No new info (linked only)
Tier C
Linux Kernel CVEs3d ago
CVE-2026-43312: media: i2c: ov5647: Initialize subdev before controls
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
f2a1998bc0053ebfe137f65081ed13afd9f3450259e372aa4cf60e2500eba7f978acdcb18bb49032cabd025182cfed4a19b3aab57493e312d681e3982dedda97a64e7735844609c6c77c0dd953d738338ecb21c20387cc0c8aa00489a21ccc69f6b0f5d1fb69e4842f5b463ff5f121d2ac7746014e3477eaeee13cbccacb6d0a3120c126b8544030905b069d05.15.2026.1.1656.6.1286.12.756.18.166.19.67.0
PublishedMay 8, 2026
Last enriched3d agov2
Trending Score63
Source articles3
Independent3
Info Completeness7/14
Missing: cvss, epss, cwe, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-31431EXPKEV
crypto: algif_aead - Revert to operating out-of-place
Trending: 122
IMPORTANTCVE-2026-43284EXP
xfrm: esp: avoid in-place decrypt on shared skb frags
Trending: 89
CRITICALCVE-2025-71301EXP
drm/tests: shmem: Hold reservation lock around vmap/vunmap
Trending: 63
CRITICALCVE-2025-71300EXP
Revert "arm64: zynqmp: Add an OP-TEE node to the device tree"
Trending: 63
CRITICALCVE-2026-43289EXP
kexec: derive purgatory entry from symbol
Trending: 63

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 8, 2026
Actively Exploited
May 8, 2026
Patch Available
May 8, 2026
Discovered by ZDM
May 8, 2026
Updated: description, severity, affectedVersions, activelyExploited
May 8, 2026

Version History

v2
Last enriched 3d ago
v2Tier C3d ago

Updated severity to CRITICAL, added affected version 6.19.5, and corrected exploit availability to false.

descriptionseverityaffectedVersionsactivelyExploited
via VulDB
v13d ago

Initial creation