7.0

CVSS3.1

CVE-2025-40220 - fuse: fix livelock in synchronous file put from fuseblk workers

In the Linux kernel, the following vulnerability has been resolved: fuse: fix livelock in synchronous file put from fuseblk workers I observed a hang when running generic/323 against a fuseblk server. This test opens a file, initiates a lot of AIO writes to that file descriptor, and closes the fi…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

6.1

CVSS3.1

CVE-2025-63499 -

Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:24 p.m.

7.0

CVSS3.1

CVE-2025-40264 - be2net: pass wrb_params in case of OS2BMC

In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pkt_to_bmc() call site.Β  This may lead to dereferencing a NULL pointer when processing a workaround fo…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40263 - Input: cros_ec_keyb - fix an invalid memory access

In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`) in cros_ec_keyb_probe(), `ckdev->idev` remains NULL. An invalid memory access is observed in cros…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 4:16 p.m.

0.0

CVE-2025-40262 - Input: imx_sc_key - fix memory corruption on unload

In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&priv" which is an address in the stack and so it will lead to memory corruption when the imx_sc_key_action() function is…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

7.0

CVSS3.1

CVE-2025-40259 - scsi: sg: Do not sleep in atomic context

In the Linux kernel, the following vulnerability has been resolved: scsi: sg: Do not sleep in atomic context sg_finish_rem_req() calls blk_rq_unmap_user(). The latter function may sleep. Hence, call sg_finish_rem_req() with interrupts enabled instead of disabled.

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

7.0

CVSS3.1

CVE-2025-40254 - net: openvswitch: remove never-working support for setting nsh fields

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: remove never-working support for setting nsh fields The validation of the set(nsh(...)) action is completely wrong. It runs through the nsh_key_put_from_nlattr() function that is the same function that validates…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

5.5

CVSS3.1

CVE-2025-40233 - ocfs2: clear extent cache after moving/defragmenting extents

In the Linux kernel, the following vulnerability has been resolved: ocfs2: clear extent cache after moving/defragmenting extents The extent map cache can become stale when extents are moved or defragmented, causing subsequent operations to see outdated extent flags. This triggers a BUG_ON in ocf…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 4, 2025, 5:15 p.m.

5.5

CVSS3.1

CVE-2025-40219 - PCI/IOV: Fix race between SR-IOV enable/disable and hotplug

In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Fix race between SR-IOV enable/disable and hotplug Commit 05703271c3cd ("PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV") tried to fix a race between the VF removal inside sriov_del_vfs() and concu…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: April 3, 2026, 4:16 p.m.

7.0

CVSS3.1

CVE-2025-40248 - vsock: Ignore signal/timeout on connect() if already established

In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if already established During connect(), acting on a signal/timeout by disconnecting an already established socket leads to several issues: 1. connect() invoking vsock_transport_cancel_p…

πŸ“… Published: Dec. 4, 2025, midnight πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.
Total resulsts: 344032
Page 2316 of 34,404
Β« previous page Β» next page
Filters