0.0

CVE-2025-68172 - crypto: aspeed - fix double free caused by devm

In the Linux kernel, the following vulnerability has been resolved: crypto: aspeed - fix double free caused by devm The clock obtained via devm_clk_get_enabled() is automatically managed by devres and will be disabled and freed on driver detach. Manually calling clk_disable_unprepare() in error p…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

0.0

CVE-2025-68256 - staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser The Information Element (IE) parser rtw_get_ie() trusted the length byte of each IE without validating that the IE body (len bytes after the 2-byte header) fits in…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Feb. 9, 2026, 8:31 a.m.

7.0

CVSS3.1

CVE-2025-68199 - codetag: debug: handle existing CODETAG_EMPTY in mark_objexts_empty for slabobj_ext

In the Linux kernel, the following vulnerability has been resolved: codetag: debug: handle existing CODETAG_EMPTY in mark_objexts_empty for slabobj_ext When alloc_slab_obj_exts() fails and then later succeeds in allocating a slab extension vector, it calls handle_failed_objexts_alloc() to mark al…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68233 - drm/tegra: Add call to put_pid()

In the Linux kernel, the following vulnerability has been resolved: drm/tegra: Add call to put_pid() Add a call to put_pid() corresponding to get_task_pid(). host1x_memory_context_alloc() does not take ownership of the PID so we need to free it here to avoid leaking. [[email protected]: rewo…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.0

CVSS3.1

CVE-2025-68229 - scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show()

In the Linux kernel, the following vulnerability has been resolved: scsi: target: tcm_loop: Fix segfault in tcm_loop_tpg_address_show() If the allocation of tl_hba->sh fails in tcm_loop_driver_probe() and we attempt to dereference it in tcm_loop_tpg_address_show() we will get a segfault, see belo…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

0.0

CVE-2025-68217 - Input: pegasus-notetaker - fix potential out-of-bounds access

In the Linux kernel, the following vulnerability has been resolved: Input: pegasus-notetaker - fix potential out-of-bounds access In the pegasus_notetaker driver, the pegasus_probe() function allocates the URB transfer buffer using the wMaxPacketSize value from the endpoint descriptor. An attacke…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.0

CVSS3.1

CVE-2025-68213 - idpf: fix possible vport_config NULL pointer deref in remove

In the Linux kernel, the following vulnerability has been resolved: idpf: fix possible vport_config NULL pointer deref in remove Attempting to remove the driver will cause a crash in cases where the vport failed to initialize. Following trace is from an instance where the driver failed during an …

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68200 - bpf: Add bpf_prog_run_data_pointers()

In the Linux kernel, the following vulnerability has been resolved: bpf: Add bpf_prog_run_data_pointers() syzbot found that cls_bpf_classify() is able to change tc_skb_cb(skb)->drop_reason triggering a warning in sk_skb_reason_drop(). WARNING: CPU: 0 PID: 5965 at net/core/skbuff.c:1192 __sk_skb_…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.0

CVSS3.1

CVE-2025-40350 - net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ XDP programs can change the layout of an xdp_buff through bpf_xdp_adjust_tail() and bpf_xdp_adjust_head(). Therefore, the driver cannot assume the size of…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.0

CVSS3.1

CVE-2025-68241 - ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe

In the Linux kernel, the following vulnerability has been resolved: ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe The sit driver's packet transmission path calls: sit_tunnel_xmit() -> update_or_create_fnhe(), which lead to fnhe_remove_oldest() being called to delete entries e…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.
Total resulsts: 343944
Page 2066 of 34,395
Β« previous page Β» next page
Filters