7.0

CVSS3.1

CVE-2025-40307 - exfat: validate cluster allocation bits of the allocation bitmap

In the Linux kernel, the following vulnerability has been resolved: exfat: validate cluster allocation bits of the allocation bitmap syzbot created an exfat image with cluster bits not set for the allocation bitmap. exfat-fs reads and uses the allocation bitmap without checking this. The problem โ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 20, 2025, 8:51 a.m.

7.0

CVSS3.1

CVE-2025-40292 - virtio-net: fix received length check in big packets

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix received length check in big packets Since commit 4959aebba8c0 ("virtio-net: use mtu size as buffer length for big packets"), when guest gso is off, the allocated size for big packets is not MAX_SKB_FRAGS * PAGE_Sโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

7.0

CVSS3.1

CVE-2025-40324 - NFSD: Fix crash in nfsd4_read_release()

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix crash in nfsd4_read_release() When tracing is enabled, the trace_nfsd_read_done trace point crashes during the pynfs read.testNoFh test.

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

7.0

CVSS3.1

CVE-2025-40322 - fbdev: bitblit: bound-check glyph index in bit_putcs*

In the Linux kernel, the following vulnerability has been resolved: fbdev: bitblit: bound-check glyph index in bit_putcs* bit_putcs_aligned()/unaligned() derived the glyph pointer from the character value masked by 0xff/0x1ff, which may exceed the actual font's glyph count and read past the end oโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 3:33 p.m.

5.5

CVSS3.1

CVE-2025-40315 - usb: gadget: f_fs: Fix epfile null pointer access after ep enable.

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix epfile null pointer access after ep enable. A race condition occurs when ffs_func_eps_enable() runs concurrently with ffs_data_reset(). The ffs_data_clear() called in ffs_data_reset() sets ffs->epfiles to Nโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 3:33 p.m.

5.5

CVSS3.1

CVE-2025-40311 - accel/habanalabs: support mapping cb with vmalloc-backed coherent memory

In the Linux kernel, the following vulnerability has been resolved: accel/habanalabs: support mapping cb with vmalloc-backed coherent memory When IOMMU is enabled, dma_alloc_coherent() with GFP_USER may return addresses from the vmalloc range. If such an address is mapped without VM_MIXEDMAP, vm_โ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 20, 2025, 8:52 a.m.

7.0

CVSS3.1

CVE-2025-40294 - Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern() In the parse_adv_monitor_pattern() function, the value of the 'length' variable is currently limited to HCI_MAX_EXT_AD_LENGTH(251). The size of the 'value' array in tโ€ฆ

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 8, 2025, 6:26 p.m.

6.1

CVSS3.1

CVE-2025-65231 -

Barix Instreamer v04.06 and earlier is vulnerable to Cross Site Scripting (XSS) in the Web UI I/O & Serial configuration page, specifically the CTS close command user-input field which is stored and later rendered on the Status page.

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 17, 2025, 3:26 p.m.

7.2

CVSS3.1

CVE-2025-65363 -

Authenticated append-style command-injection Ruijie APs (AP_RGOS 11.1.x) allows an authenticated web user to execute appended shell expressions as root, enabling file disclosure, device disruption, and potential network pivoting via the command parameter to the web_action.do endpoint.

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 12, 2025, 12:33 p.m.

0.0

CVE-2025-67045 -

DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-67041. Reason: This record is a reservation duplicate of CVE-2025-67041. Notes: All CVE users should reference CVE-2025-67041 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

๐Ÿ“… Published: Dec. 8, 2025, midnight ๐Ÿ”„ Last Modified: Dec. 19, 2025, 3:58 p.m.
Total resulsts: 342218
Page 2096 of 34,222
ยซ previous page ยป next page
Filters