7.0

CVSS3.1

CVE-2025-40344 - ASoC: Intel: avs: Disable periods-elapsed work when closing PCM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: avs: Disable periods-elapsed work when closing PCM avs_dai_fe_shutdown() handles the shutdown procedure for HOST HDAudio stream while period-elapsed work services its IRQs. As the former frees the DAI's private conte…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:36 p.m.

7.0

CVSS3.1

CVE-2023-53860 - dm: don't attempt to queue IO under RCU protection

In the Linux kernel, the following vulnerability has been resolved: dm: don't attempt to queue IO under RCU protection dm looks up the table for IO based on the request type, with an assumption that if the request is marked REQ_NOWAIT, it's fine to attempt to submit that IO while under RCU read l…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2023-53816 - drm/amdkfd: fix potential kgd_mem UAFs

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix potential kgd_mem UAFs kgd_mem pointers returned by kfd_process_device_translate_handle are only guaranteed to be valid while p->mutex is held. As soon as the mutex is unlocked, another thread can free the BO.

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 20, 2025, 8:51 a.m.

7.0

CVSS3.1

CVE-2023-53811 - RDMA/irdma: Cap MSIX used to online CPUs + 1

In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Cap MSIX used to online CPUs + 1 The irdma driver can use a maximum number of msix vectors equal to num_online_cpus() + 1 and the kernel warning stack below is shown if that number is exceeded. The kernel throws a wa…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

7.0

CVSS3.1

CVE-2023-53791 - md: fix warning for holder mismatch from export_rdev()

In the Linux kernel, the following vulnerability has been resolved: md: fix warning for holder mismatch from export_rdev() Commit a1d767191096 ("md: use mddev->external to select holder in export_rdev()") fix the problem that 'claim_rdev' is used for blkdev_get_by_dev() while 'rdev' is used for b…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2022-50648 - ftrace: Fix recursive locking direct_mutex in ftrace_modify_direct_caller

In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix recursive locking direct_mutex in ftrace_modify_direct_caller Naveen reported recursive locking of direct_mutex with sample ftrace-direct-modify.ko: [ 74.762406] WARNING: possible recursive locking detected [ 74.…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

5.5

CVSS3.1

CVE-2022-50639 - io-wq: Fix memory leak in worker creation

In the Linux kernel, the following vulnerability has been resolved: io-wq: Fix memory leak in worker creation If the CPU mask allocation for a node fails, then the memory allocated for the 'io_wqe' struct of the current node doesn't get freed on the error handling path, since it has not yet been …

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 9, 2025, 6:37 p.m.

8.1

CVSS3.1

CVE-2025-65594 -

OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users.

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 11, 2025, 8:16 p.m.

6.5

CVSS3.1

CVE-2025-65288 -

A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and stores excessively long hostnames from LAN hosts without proper length validation. The affected code performs unchecked copies/concatenations into fixed-size buffers. A crafted long …

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 12, 2025, 2:32 p.m.

7.0

CVSS3.1

CVE-2025-40343 - nvmet-fc: avoid scheduling association deletion twice

In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twice When forcefully shutting down a port via the configfs interface, nvmet_port_subsys_drop_link() first calls nvmet_port_del_ctrls() and then nvmet_disable_port(). Both functions…

πŸ“… Published: Dec. 9, 2025, midnight πŸ”„ Last Modified: Dec. 20, 2025, 8:52 a.m.
Total resulsts: 343924
Page 2240 of 34,393
Β« previous page Β» next page
Filters