7.0

CVSS3.1

CVE-2025-39725 - mm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list

In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: fix hwpoisoned large folio handling in shrink_folio_list In shrink_folio_list(), the hwpoisoned folio may be large folio, which can't be handled by unmap_poisoned_folio(). For THP, try_to_unmap_one() must be passed wi…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-38735 - gve: prevent ethtool ops after shutdown

In the Linux kernel, the following vulnerability has been resolved: gve: prevent ethtool ops after shutdown A crash can occur if an ethtool operation is invoked after shutdown() is called. shutdown() is invoked during system shutdown to stop DMA operations without performing expensive deallocati…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-38737 - cifs: Fix oops due to uninitialised variable

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before calling netfs_alloc_folioq_buffer() as netfs assumes it can append to the buffer it is given. Setting it to NULL means…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-39702 - ipv6: sr: Fix MAC comparison to be constant-time

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

4.3

CVSS3.1

CVE-2025-10044 - Keycloak: keycloak error_description injection on error pages

A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XSS, an attacker can craft URLs with misleading mes…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-39716 - parisc: Revise __get_user() to probe user read access

In the Linux kernel, the following vulnerability has been resolved: parisc: Revise __get_user() to probe user read access Because of the way read access support is implemented, read access interruptions are only triggered at privilege levels 2 and 3. The kernel executes at privilege level 0, so _…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-39708 - media: iris: Fix NULL pointer dereference

In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix NULL pointer dereference A warning reported by smatch indicated a possible null pointer dereference where one of the arguments to API "iris_hfi_gen2_handle_system_error" could sometimes be null. To fix this, add…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-39680 - i2c: rtl9300: Fix out-of-bounds bug in rtl9300_i2c_smbus_xfer

In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: Fix out-of-bounds bug in rtl9300_i2c_smbus_xfer The data->block[0] variable comes from user. Without proper check, the variable may be very large to cause an out-of-bounds bug. Fix this bug by checking the value of…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-39693 - drm/amd/display: Avoid a NULL pointer dereference

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid a NULL pointer dereference [WHY] Although unlikely drm_atomic_get_new_connector_state() or drm_atomic_get_old_connector_state() can return NULL. [HOW] Check returns before dereference. (cherry picked from…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 3:21 p.m.

7.0

CVSS3.1

CVE-2025-39722 - crypto: caam - Prevent crash on suspend with iMX8QM / iMX8ULP

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - Prevent crash on suspend with iMX8QM / iMX8ULP Since the CAAM on these SoCs is managed by another ARM core, called the SECO (Security Controller) on iMX8QM and Secure Enclave on iMX8ULP, which also reserves access …

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.
Total resulsts: 309334
Page 101 of 30,934
Β« previous page Β» next page
Filters