5.5

CVSS3.1

CVE-2025-39724 - serial: 8250: fix panic due to PSLVERR

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: fix panic due to PSLVERR When the PSLVERR_RESP_EN parameter is set to 1, the device generates an error response if an attempt is made to read an empty RBR (Receive Buffer Register) while the FIFO is enabled. In ser…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-39691 - fs/buffer: fix use-after-free when call bh_read() helper

In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() helper There's issue as follows: BUG: KASAN: stack-out-of-bounds in end_buffer_read_sync+0xe3/0x110 Read of size 8 at addr ffffc9000168f7f8 by task swapper/3/0 CPU: 3 UID: 0 PID: …

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-39683 - tracing: Limit access to parser->buffer when trace_get_user failed

In the Linux kernel, the following vulnerability has been resolved: tracing: Limit access to parser->buffer when trace_get_user failed When the length of the string written to set_ftrace_filter exceeds FTRACE_BUFF_MAX, the following KASAN alarm will be triggered: BUG: KASAN: slab-out-of-bounds i…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

2.7

CVSS3.1

CVE-2025-10043 - Keycloak: incomplete fix of cve-2024-10492

A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous fix for CVE-2024-10492 did not account for the Windows file separator (\). As a result, a high-privilege administrator could probe for the existence of files outside the expected realm context through …

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-39700 - mm/damon/ops-common: ignore migration request to invalid nodes

In the Linux kernel, the following vulnerability has been resolved: mm/damon/ops-common: ignore migration request to invalid nodes damon_migrate_pages() tries migration even if the target node is invalid. If users mistakenly make such invalid requests via DAMOS_MIGRATE_{HOT,COLD} action, the bel…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-39696 - ALSA: hda: tas2781: Fix wrong reference of tasdevice_priv

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: tas2781: Fix wrong reference of tasdevice_priv During the conversion to unify the calibration data management, the reference to tasdevice_priv was wrongly set to h->hda_priv instead of h->priv. This resulted in memory…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-39673 - ppp: fix race conditions in ppp_fill_forward_path

In the Linux kernel, the following vulnerability has been resolved: ppp: fix race conditions in ppp_fill_forward_path ppp_fill_forward_path() has two race conditions: 1. The ppp->channels list can change between list_empty() and list_first_entry(), as ppp_lock() is not held. If the only chann…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-38733 - s390/mm: Do not map lowcore with identity mapping

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Do not map lowcore with identity mapping Since the identity mapping is pinned to address zero the lowcore is always also mapped to address zero, this happens regardless of the relocate_lowcore command line option. If the…

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-39722 - crypto: caam - Prevent crash on suspend with iMX8QM / iMX8ULP

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - Prevent crash on suspend with iMX8QM / iMX8ULP Since the CAAM on these SoCs is managed by another ARM core, called the SECO (Security Controller) on iMX8QM and Secure Enclave on iMX8ULP, which also reserves access …

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.

7.0

CVSS3.1

CVE-2025-39717 - open_tree_attr: do not allow id-mapping changes without OPEN_TREE_CLONE

In the Linux kernel, the following vulnerability has been resolved: open_tree_attr: do not allow id-mapping changes without OPEN_TREE_CLONE As described in commit 7a54947e727b ('Merge patch series "fs: allow changing idmappings"'), open_tree_attr(2) was necessary in order to allow for a detached …

πŸ“… Published: Sept. 5, 2025, midnight πŸ”„ Last Modified: Sept. 8, 2025, 4:25 p.m.
Total resulsts: 309781
Page 144 of 30,979
Β« previous page Β» next page
Filters