5.5

CVSS3.1

CVE-2025-40169 - bpf: Reject negative offsets for ALU ops

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative offsets for ALU ops When verifying BPF programs, the check_alu_op() function validates instructions with ALU operations. The 'offset' field in these instructions is a signed 16-bit integer. The existing chec…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:19 a.m.

7.0

CVSS3.1

CVE-2025-40160 - xen/events: Return -EEXIST for bound VIRQs

In the Linux kernel, the following vulnerability has been resolved: xen/events: Return -EEXIST for bound VIRQs Change find_virq() to return -EEXIST when a VIRQ is bound to a different CPU than the one passed in. With that, remove the BUG_ON() from bind_virq_to_irq() to propogate the error upward…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:33 p.m.

5.5

CVSS3.1

CVE-2025-40126 - sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC

In the Linux kernel, the following vulnerability has been resolved: sparc: fix accurate exception reporting in copy_{from_to}_user for UltraSPARC The referenced commit introduced exception handlers on user-space memory references in copy_from_user and copy_to_user. These handlers return from the …

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:18 a.m.

5.5

CVSS3.1

CVE-2025-40125 - blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx

In the Linux kernel, the following vulnerability has been resolved: blk-mq: check kobject state_in_sysfs before deleting in blk_mq_unregister_hctx In __blk_mq_update_nr_hw_queues() the return value of blk_mq_sysfs_register_hctxs() is not checked. If sysfs creation for hctx fails, later changing t…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:18 a.m.

7.0

CVSS3.1

CVE-2025-40121 - ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping When an invalid value is passed via quirk option, currently bytcr_rt5640 driver just ignores and leaves as is, which may lead to unepxected results like OOB access. This…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:18 a.m.

7.0

CVSS3.1

CVE-2025-40110 - drm/vmwgfx: Fix a null-ptr access in the cursor snooper

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a null-ptr access in the cursor snooper Check that the resource which is converted to a surface exists before trying to use the cursor snooper on it. vmw_cmd_res_check allows explicit invalid (SVGA3D_INVALID_ID) …

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Jan. 19, 2026, 1:16 p.m.

5.5

CVSS3.1

CVE-2025-40164 - usbnet: Fix using smp_processor_id() in preemptible code warnings

In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible code warnings Syzbot reported the following warning: BUG: using smp_processor_id() in preemptible [00000000] code: dhcpcd/2879 caller is usbnet_skb_return+0x74/0x490 drivers/ne…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 3:52 p.m.

7.5

CVSS3.1

CVE-2025-63811 -

An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS) via crafted JSON Web Encryption (JWE) token with an exceptionally high compression ratio.

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 4:26 p.m.

6.1

CVSS3.1

CVE-2025-63419 -

Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects the filename to an emailbody field with no sanitations leading to HTML Injection.

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 4:34 p.m.

7.0

CVSS3.1

CVE-2025-40157 - EDAC/i10nm: Skip DIMM enumeration on a disabled memory controller

In the Linux kernel, the following vulnerability has been resolved: EDAC/i10nm: Skip DIMM enumeration on a disabled memory controller When loading the i10nm_edac driver on some Intel Granite Rapids servers, a call trace may appear as follows: UBSAN: shift-out-of-bounds in drivers/edac/skx_comm…

πŸ“… Published: Nov. 12, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:19 a.m.
Total resulsts: 342311
Page 2366 of 34,232
Β« previous page Β» next page
Filters