5.5

CVSS3.1

CVE-2025-68245 - net: netpoll: fix incorrect refcount handling causing incorrect cleanup

In the Linux kernel, the following vulnerability has been resolved: net: netpoll: fix incorrect refcount handling causing incorrect cleanup commit efa95b01da18 ("netpoll: fix use after free") incorrectly ignored the refcount and prematurely set dev->npinfo to NULL during netpoll cleanup, leading …

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

0.0

CVE-2025-68240 - nilfs2: avoid having an active sc_timer before freeing sci

In the Linux kernel, the following vulnerability has been resolved: nilfs2: avoid having an active sc_timer before freeing sci Because kthread_stop did not stop sc_task properly and returned -EINTR, the sc_timer was not properly closed, ultimately causing the problem [1] reported by syzbot when f…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68169 - netpoll: Fix deadlock in memory allocation under spinlock

In the Linux kernel, the following vulnerability has been resolved: netpoll: Fix deadlock in memory allocation under spinlock Fix a AA deadlock in refill_skbs() where memory allocation while holding skb_pool->lock can trigger a recursive lock acquisition attempt. The deadlock scenario occurs whe…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68306 - Bluetooth: btusb: mediatek: Fix kernel crash when releasing mtk iso interface

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix kernel crash when releasing mtk iso interface When performing reset tests and encountering abnormal card drop issues that lead to a kernel crash, it is necessary to perform a null check before rele…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68264 - ext4: refresh inline data size before write operations

In the Linux kernel, the following vulnerability has been resolved: ext4: refresh inline data size before write operations The cached ei->i_inline_size can become stale between the initial size check and when ext4_update_inline_data()/ext4_create_inline_data() use it. Although ext4_get_max_inline…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Feb. 9, 2026, 8:31 a.m.

5.5

CVSS3.1

CVE-2025-68236 - scsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3)

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: ufs-qcom: Fix UFS OCP issue during UFS power down (PC=3) According to UFS specifications, the power-off sequence for a UFS device includes: - Sending an SSU command with Power_Condition=3 and await a response. - As…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:34 p.m.

5.5

CVSS3.1

CVE-2025-68170 - drm/radeon: Do not kfree() devres managed rdev

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Do not kfree() devres managed rdev Since the allocation of the drivers main structure was changed to devm_drm_dev_alloc() rdev is managed by devres and we shouldn't be calling kfree() on it. This fixes things explodi…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

0.0

CVE-2025-68316 - scsi: ufs: core: Fix invalid probe error return value

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix invalid probe error return value After DME Link Startup, the error return value is set to the MIPI UniPro GenericErrorCode which can be 0 (SUCCESS) or 1 (FAILURE). Upon failure during driver probe, the error…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

4.6

CVSS3.1

CVE-2025-62862 -

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM Boot Error Record Table driver that could result in (1) an out-of-bounds read which leaks Secure-EL0 information to a process r…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 12:28 a.m.

6.1

CVSS3.1

CVE-2025-65592 -

nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloads inserted into the "Product Name" and "Short Description" fields are stored in the backend database and executed automatically whenever a user views the affected pages.

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 4:40 p.m.
Total resulsts: 343926
Page 2071 of 34,393
Β« previous page Β» next page
Filters