5.5

CVSS3.1

CVE-2025-38152 - remoteproc: core: Clear table_sz when rproc_shutdown

In the Linux kernel, the following vulnerability has been resolved: remoteproc: core: Clear table_sz when rproc_shutdown There is case as below could trigger kernel dump: Use U-Boot to start remote processor(rproc) with resource table published to a fixed address by rproc. After Kernel boots up, …

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2025-37860 - sfc: fix NULL dereferences in ef100_process_design_param()

In the Linux kernel, the following vulnerability has been resolved: sfc: fix NULL dereferences in ef100_process_design_param() Since cited commit, ef100_probe_main() and hence also ef100_check_design_params() run before efx->net_dev is created; consequently, we cannot netif_set_tso_max_size() o…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2025-37785 - ext4: fix OOB read when checking dotdot dir

In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bounds read (later on, when the corrupted directory is removed).…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2025-40325 - md/raid10: wait barrier before returning discard request with REQ_NOWAIT

In the Linux kernel, the following vulnerability has been resolved: md/raid10: wait barrier before returning discard request with REQ_NOWAIT raid10_handle_discard should wait barrier before returning a discard bio which has REQ_NOWAIT. And there is no need to print warning calltrace if a discard …

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2025-39989 - x86/mce: use is_copy_from_user() to determine copy-from-user context

In the Linux kernel, the following vulnerability has been resolved: x86/mce: use is_copy_from_user() to determine copy-from-user context Patch series "mm/hwpoison: Fix regressions in memory failure handling", v4. ## 1. What am I trying to do: This patchset resolves two critical regressions rela…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2025-39735 - jfs: fix slab-out-of-bounds read in ea_get()

In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds read in ea_get() During the "size_check" label in ea_get(), the code checks if the extended attribute list (xattr) size matches ea_size. If not, it logs "ea_get: invalid extended attribute" and calls p…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.5

CVSS3.1

CVE-2025-37925 - jfs: reject on-disk inodes of an unsupported type

In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type Syzbot has reported the following BUG: kernel BUG at fs/inode.c:668! Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 3 UID: 0 PID: 139 Comm: jfsCommit Not tainted 6.12…

πŸ“… Published: April 18, 2025, midnight πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

8.6

CVSS4.0

CVE-2025-3246 - Markdown math block sanitization bypass allows privilege escalation and unauthorized workflow trigg…

An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the ma…

πŸ“… Published: April 17, 2025, 10:50 p.m. πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

7.1

CVSS4.0

CVE-2025-3509 - Pre-Receive Hook Remote Code Execution vulnerability was identified in GitHub Enterprise Server tha…

A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromise. The vulnerability involves using dynamically a…

πŸ“… Published: April 17, 2025, 10:50 p.m. πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.

5.3

CVSS4.0

CVE-2025-3124 - Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed unautho…

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only usin…

πŸ“… Published: April 17, 2025, 10:50 p.m. πŸ”„ Last Modified: April 21, 2025, 2:23 p.m.
Total resulsts: 291029
Page 22 of 29,103
Β« previous page Β» next page
Filters