0.0

CVE-2025-39905 - net: phylink: add lock for serializing concurrent pl->phydev writes with resolver

In the Linux kernel, the following vulnerability has been resolved: net: phylink: add lock for serializing concurrent pl->phydev writes with resolver Currently phylink_resolve() protects itself against concurrent phylink_bringup_phy() or phylink_disconnect_phy() calls which modify pl->phydev by r…

πŸ“… Published: Oct. 1, 2025, 7:44 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:40 a.m.

0.0

CVE-2025-39904 - arm64: kexec: initialize kexec_buf struct in load_other_segments()

In the Linux kernel, the following vulnerability has been resolved: arm64: kexec: initialize kexec_buf struct in load_other_segments() Patch series "kexec: Fix invalid field access". The kexec_buf structure was previously declared without initialization. commit bf454ec31add ("kexec_file: allow …

πŸ“… Published: Oct. 1, 2025, 7:44 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:40 a.m.

0.0

CVE-2025-39903 - of_numa: fix uninitialized memory nodes causing kernel panic

In the Linux kernel, the following vulnerability has been resolved: of_numa: fix uninitialized memory nodes causing kernel panic When there are memory-only nodes (nodes without CPUs), these nodes are not properly initialized, causing kernel panic during boot. of_numa_init of_numa_parse_cpu_node…

πŸ“… Published: Oct. 1, 2025, 7:42 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:40 a.m.

0.0

CVE-2025-39902 - mm/slub: avoid accessing metadata when pointer is invalid in object_err()

In the Linux kernel, the following vulnerability has been resolved: mm/slub: avoid accessing metadata when pointer is invalid in object_err() object_err() reports details of an object for further debugging, such as the freelist pointer, redzone, etc. However, if the pointer is invalid, attempting…

πŸ“… Published: Oct. 1, 2025, 7:42 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:40 a.m.

0.0

CVE-2025-39901 - i40e: remove read access to debugfs files

In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'command' and 'netdev_ops' debugfs files are a legacy debugging interface supported by the i40e driver since its early days by commit 02e9c290814c ("i40e: debugfs interface"). Both o…

πŸ“… Published: Oct. 1, 2025, 7:42 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:40 a.m.

0.0

CVE-2025-39900 - net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y

In the Linux kernel, the following vulnerability has been resolved: net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y syzbot reported a WARNING in est_timer() [1] Problem here is that with CONFIG_PREEMPT_RT=y, timer callbacks can be preempted. Adopt preempt_disable_nested()/preem…

πŸ“… Published: Oct. 1, 2025, 7:42 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:45 a.m.

0.0

CVE-2025-39899 - mm/userfaultfd: fix kmap_local LIFO ordering for CONFIG_HIGHPTE

In the Linux kernel, the following vulnerability has been resolved: mm/userfaultfd: fix kmap_local LIFO ordering for CONFIG_HIGHPTE With CONFIG_HIGHPTE on 32-bit ARM, move_pages_pte() maps PTE pages using kmap_local_page(), which requires unmapping in Last-In-First-Out order. The current code ma…

πŸ“… Published: Oct. 1, 2025, 7:42 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:46 a.m.

0.0

CVE-2025-39898 - e1000e: fix heap overflow in e1000_set_eeprom

In the Linux kernel, the following vulnerability has been resolved: e1000e: fix heap overflow in e1000_set_eeprom Fix a possible heap overflow in e1000_set_eeprom function by adding input validation for the requested length of the change in the EEPROM. In addition, change the variable type from i…

πŸ“… Published: Oct. 1, 2025, 7:42 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:46 a.m.

0.0

CVE-2025-39897 - net: xilinx: axienet: Add error handling for RX metadata pointer retrieval

In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Add error handling for RX metadata pointer retrieval Add proper error checking for dmaengine_desc_get_metadata_ptr() which can return an error pointer and lead to potential crashes or undefined behaviour if …

πŸ“… Published: Oct. 1, 2025, 7:42 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:46 a.m.

0.0

CVE-2025-39896 - accel/ivpu: Prevent recovery work from being queued during device removal

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued during device removal Use disable_work_sync() instead of cancel_work_sync() in ivpu_dev_fini() to ensure that no new recovery work items can be queued after device removal has s…

πŸ“… Published: Oct. 1, 2025, 7:42 a.m. πŸ”„ Last Modified: Oct. 2, 2025, 8:46 a.m.
Total resulsts: 312535
Page 22 of 31,254
Β« previous page Β» next page
Filters