7.5

CVSS3.1

CVE-2026-22990 - libceph: replace overzealous BUG_ON in osdmap_apply_incremental()

In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() If the osdmap is (maliciously) corrupted such that the incremental osdmap epoch is different from what is expected, there is no need to BUG. Instead, just declare…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 2:01 p.m.

9.8

CVSS3.1

CVE-2026-22984 - libceph: prevent potential out-of-bounds reads in handle_auth_done()

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in handle_auth_done() Perform an explicit bounds check on payload_len to avoid a possible out-of-bounds access in the callout. [ idryomov: changelog ]

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 2:01 p.m.

5.5

CVSS3.1

CVE-2026-22982 - net: mscc: ocelot: Fix crash when adding interface under a lag

In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix crash when adding interface under a lag Commit 15faa1f67ab4 ("lan966x: Fix crash when adding interface under a lag") fixed a similar issue in the lan966x driver caused by a NULL pointer dereference. The oce…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 7 p.m.

7.5

CVSS3.1

CVE-2025-70986 -

Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Jan. 30, 2026, 9:26 p.m.

5.5

CVSS3.1

CVE-2026-22981 - idpf: detach and close netdevs while handling a reset

In the Linux kernel, the following vulnerability has been resolved: idpf: detach and close netdevs while handling a reset Protect the reset path from callbacks by setting the netdevs to detached state and close any netdevs in UP state until the reset handling has completed. During a reset, the dr…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 15, 2026, 9:45 p.m.

5.5

CVSS3.1

CVE-2025-71161 - dm-verity: disable recursive forward error correction

In the Linux kernel, the following vulnerability has been resolved: dm-verity: disable recursive forward error correction There are two problems with the recursive correction: 1. It may cause denial-of-service. In fec_read_bufs, there is a loop that has 253 iterations. For each iteration, we may…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 11:16 a.m.

7.8

CVSS3.1

CVE-2025-71152 - net: dsa: properly keep track of conduit reference

In the Linux kernel, the following vulnerability has been resolved: net: dsa: properly keep track of conduit reference Problem description ------------------- DSA has a mumbo-jumbo of reference handling of the conduit net device and its kobject which, sadly, is just wrong and doesn't make sense.…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: March 25, 2026, 11:16 a.m.

5.5

CVSS3.1

CVE-2026-22979 - net: fix memory leak in skb_segment_list for GRO packets

In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO packets When skb_segment_list() is called during packet forwarding, it handles packets that were aggregated by the GRO engine. Historically, the segmentation logic in skb_segment_…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 18, 2026, 8 p.m.

7.5

CVSS3.1

CVE-2026-22992 - libceph: return the handler error from mon_handle_auth_done()

In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_auth_done() Currently any error from ceph_auth_handle_reply_done() is propagated via finish_auth() but isn't returned from mon_handle_auth_done(). This results in higher layers l…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: April 27, 2026, 2:02 p.m.

7.5

CVSS3.1

CVE-2025-69908 -

An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript resource.

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:42 p.m.
Total resulsts: 349182
Page 1988 of 34,919
Β« previous page Β» next page
Filters