2.8

CVSS3.1

CVE-2025-44021 - openstack-ironic: unsafe image file:// paths

OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can provide a path to any local file (readable by ironic-conductor), which may then be written to the targe…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 9:15 p.m.

7.0

CVSS3.1

CVE-2025-37834 - mm/vmscan: don't try to reclaim hwpoison folio

In the Linux kernel, the following vulnerability has been resolved: mm/vmscan: don't try to reclaim hwpoison folio Syzkaller reports a bug as follows: Injecting memory failure for pfn 0x18b00e at process virtual address 0x20ffd000 Memory failure: 0x18b00e: dirty swapcache page still referenced b…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

7.0

CVSS3.1

CVE-2025-37832 - cpufreq: sun50i: prevent out-of-bounds access

In the Linux kernel, the following vulnerability has been resolved: cpufreq: sun50i: prevent out-of-bounds access A KASAN enabled kernel reports an out-of-bounds access when handling the nvmem cell in the sun50i cpufreq driver: ================================================================== BU…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

7.0

CVSS3.1

CVE-2025-37831 - cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()

In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate() cpufreq_cpu_get_raw() can return NULL when the target CPU is not present in the policy->cpus mask. apple_soc_cpufreq_get_rate() does not check for this case, …

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-37830 - cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate()

In the Linux kernel, the following vulnerability has been resolved: cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate() cpufreq_cpu_get_raw() can return NULL when the target CPU is not present in the policy->cpus mask. scmi_cpufreq_get_rate() does not check for this case, which results i…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-37829 - cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()

In the Linux kernel, the following vulnerability has been resolved: cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate() cpufreq_cpu_get_raw() can return NULL when the target CPU is not present in the policy->cpus mask. scpi_cpufreq_get_rate() does not check for this case, which results i…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-37828 - scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort()

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort() A race can occur between the MCQ completion path and the abort handler: once a request completes, __blk_mq_free_request() sets rq->mq_hctx to NULL, meaning the subsequent ufshc…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

7.0

CVSS3.1

CVE-2025-37826 - scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer()

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer() Add a NULL check for the returned hwq pointer by ufshcd_mcq_req_to_hwq(). This is similar to the fix in commit 74736103fb41 ("scsi: ufs: core: Fix ufshcd_abo…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-37825 - nvmet: fix out-of-bounds access in nvmet_enable_port

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix out-of-bounds access in nvmet_enable_port When trying to enable a port that has no transport configured yet, nvmet_enable_port() uses NVMF_TRTYPE_MAX (255) to query the transports array, causing an out-of-bounds access…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-37824 - tipc: fix NULL pointer dereference in tipc_mon_reinit_self()

In the Linux kernel, the following vulnerability has been resolved: tipc: fix NULL pointer dereference in tipc_mon_reinit_self() syzbot reported: tipc: Node number set to 1055423674 Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI K…

πŸ“… Published: May 8, 2025, midnight πŸ”„ Last Modified: May 8, 2025, 2:39 p.m.
Total resulsts: 293427
Page 27 of 29,343
Β« previous page Β» next page
Filters