5.5

CVSS3.1

CVE-2025-71149 - io_uring/poll: correctly handle io_poll_add() return value on update

In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: correctly handle io_poll_add() return value on update When the core of io_uring was updated to handle completions consistently and with fixed return codes, the POLL_REMOVE opcode with updates got slightly broken. I…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:28 p.m.

3.3

CVSS3.1

CVE-2025-71148 - net/handshake: restore destructor on submit failure

In the Linux kernel, the following vulnerability has been resolved: net/handshake: restore destructor on submit failure handshake_req_submit() replaces sk->sk_destruct but never restores it when submission fails before the request is hashed. handshake_sk_destruct() then returns early and the orig…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:27 p.m.

5.5

CVSS3.1

CVE-2025-71147 - KEYS: trusted: Fix a memory leak in tpm2_load_cmd

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix a memory leak in tpm2_load_cmd 'tpm2_load_cmd' allocates a tempoary blob indirectly via 'tpm2_key_decode' but it is not freed in the failure paths. Address this by wrapping the blob into with a cleanup helper.

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:26 p.m.

7.8

CVSS3.1

CVE-2025-71157 - RDMA/core: always drop device refcount in ib_del_sub_device_and_put()

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: always drop device refcount in ib_del_sub_device_and_put() Since nldev_deldev() (introduced by commit 060c642b2ab8 ("RDMA/nldev: Add support to add/delete a sub IB device through netlink") grabs a reference using ib_de…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:22 p.m.

7.8

CVSS3.1

CVE-2025-71159 - btrfs: fix use-after-free warning in btrfs_get_or_create_delayed_node()

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free warning in btrfs_get_or_create_delayed_node() Previously, btrfs_get_or_create_delayed_node() set the delayed_node's refcount before acquiring the root->delayed_nodes lock. Commit e8513c012de7 ("btrfs: im…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:19 p.m.

9.9

CVSS3.1

CVE-2025-70983 -

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:28 p.m.

5.5

CVSS3.1

CVE-2025-71153 - ksmbd: Fix memory leak in get_file_all_info()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix memory leak in get_file_all_info() In get_file_all_info(), if vfs_getattr() fails, the function returns immediately without freeing the allocated filename, leading to a memory leak. Fix this by freeing the filename be…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:30 p.m.

5.5

CVSS3.1

CVE-2025-71146 - netfilter: nf_conncount: fix leaked ct in error paths

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: fix leaked ct in error paths There are some situations where ct might be leaked as error paths are skipping the refcounted check and return immediately. In order to solve it make sure that the check is al…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:25 p.m.

4.7

CVSS3.1

CVE-2026-22986 - gpiolib: fix race condition for gdev->srcu

In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix race condition for gdev->srcu If two drivers were calling gpiochip_add_data_with_key(), one may be traversing the srcu-protected list in gpio_name_to_desc(), meanwhile other has just added its gdev in gpiodev_add_to_…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 1:16 p.m.

5.3

CVSS3.1

CVE-2025-52022 -

A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests are sent to public…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:25 p.m.
Total resulsts: 346576
Page 1727 of 34,658
Β« previous page Β» next page
Filters