7.0

CVSS3.1

CVE-2023-53803 - scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process()

In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix slab-out-of-bounds in ses_enclosure_data_process() A fix for: BUG: KASAN: slab-out-of-bounds in ses_enclosure_data_process+0x949/0xe30 [ses] Read of size 1 at addr ffff88a1b043a451 by task systemd-udevd/3271 Chec…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:32 a.m.

7.0

CVSS3.1

CVE-2023-53799 - crypto: api - Use work queue in crypto_destroy_instance

In the Linux kernel, the following vulnerability has been resolved: crypto: api - Use work queue in crypto_destroy_instance The function crypto_drop_spawn expects to be called in process context. However, when an instance is unregistered while it still has active users, the last user may cause t…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2022-50668 - ext4: fix deadlock due to mbcache entry corruption

In the Linux kernel, the following vulnerability has been resolved: ext4: fix deadlock due to mbcache entry corruption When manipulating xattr blocks, we can deadlock infinitely looping inside ext4_xattr_block_set() where we constantly keep finding xattr block for reuse in mbcache but we are unab…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2022-50661 - seccomp: Move copy_seccomp() to no failure path.

In the Linux kernel, the following vulnerability has been resolved: seccomp: Move copy_seccomp() to no failure path. Our syzbot instance reported memory leaks in do_seccomp() [0], similar to the report [1]. It shows that we miss freeing struct seccomp_filter and some objects included in it. We …

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2022-50667 - drm/vmwgfx: Fix memory leak in vmw_mksstat_add_ioctl()

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix memory leak in vmw_mksstat_add_ioctl() If the copy of the description string from userspace fails, then the page for the instance descriptor doesn't get freed before returning -EFAULT, which leads to a memleak.

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2022-50641 - HSI: omap_ssi: Fix refcount leak in ssi_probe

In the Linux kernel, the following vulnerability has been resolved: HSI: omap_ssi: Fix refcount leak in ssi_probe When returning or breaking early from a for_each_available_child_of_node() loop, we need to explicitly call of_node_put() on the child node to possibly release the node.

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2022-50651 - ethtool: eeprom: fix null-deref on genl_info in dump

In the Linux kernel, the following vulnerability has been resolved: ethtool: eeprom: fix null-deref on genl_info in dump The similar fix as commit 46cdedf2a0fa ("ethtool: pse-pd: fix null-deref on genl_info in dump") is also needed for ethtool eeprom.

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2022-50635 - powerpc/kprobes: Fix null pointer reference in arch_prepare_kprobe()

In the Linux kernel, the following vulnerability has been resolved: powerpc/kprobes: Fix null pointer reference in arch_prepare_kprobe() I found a null pointer reference in arch_prepare_kprobe(): # echo 'p cmdline_proc_show' > kprobe_events # echo 'p cmdline_proc_show+16' >> kprobe_events …

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2023-53829 - f2fs: flush inode if atomic file is aborted

In the Linux kernel, the following vulnerability has been resolved: f2fs: flush inode if atomic file is aborted Let's flush the inode being aborted atomic operation to avoid stale dirty inode during eviction in this call stack: f2fs_mark_inode_dirty_sync+0x22/0x40 [f2fs] f2fs_abort_atomic_wr…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 20, 2025, 8:51 a.m.

4.6

CVSS3.1

CVE-2025-61074 -

A stored Cross Site Scripting (XSS) vulnerability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeiter Portal 2.15.2.0 allows remote authenticated users to execute arbitrary JavaScript code in the web browser of other users via manipulation of the 'Inhalt' parameter of the '/Sch…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 3:15 p.m.
Total resulsts: 343924
Page 2239 of 34,393
Β« previous page Β» next page
Filters