7.0

CVSS3.1

CVE-2025-40000 - wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait() There is a bug observed when rtw89_core_tx_kick_off_and_wait() tries to access already freed skb_data: BUG: KFENCE: use-after-free write in rtw89_core_tx_kick…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.0

CVSS3.1

CVE-2025-39993 - media: rc: fix races with imon_disconnect()

In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot reports a KASAN issue as below: BUG: KASAN: use-after-free in __create_pipe include/linux/usb.h:1945 [inline] BUG: KASAN: use-after-free in send_packet+0xa2d/0xbc0 drivers/media/…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

5.5

CVSS3.1

CVE-2025-39995 - media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe

In the Linux kernel, the following vulnerability has been resolved: media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe The state->timer is a cyclic timer that schedules work_i2c_poll and delayed_work_enable_hotplug, while rearming itself. Using timer_delete() fails to g…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.0

CVSS3.1

CVE-2025-39992 - mm: swap: check for stable address space before operating on the VMA

In the Linux kernel, the following vulnerability has been resolved: mm: swap: check for stable address space before operating on the VMA It is possible to hit a zero entry while traversing the vmas in unuse_mm() called from swapoff path and accessing it causes the OOPS: Unable to handle kernel N…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.0

CVSS3.1

CVE-2025-39998 - scsi: target: target_core_configfs: Add length check to avoid buffer overflow

In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length check to avoid buffer overflow A buffer overflow arises from the usage of snprintf to write into the buffer "buf" in target_lu_gp_members_show function located in /drivers/target/tar…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:32 p.m.

9.4

CVSS3.1

CVE-2025-56749 -

Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 7:24 p.m.

5.5

CVSS3.1

CVE-2025-39974 - tracing/osnoise: Fix slab-out-of-bounds in _parse_integer_limit()

In the Linux kernel, the following vulnerability has been resolved: tracing/osnoise: Fix slab-out-of-bounds in _parse_integer_limit() When config osnoise cpus by write() syscall, the following KASAN splat may be observed: BUG: KASAN: slab-out-of-bounds in _parse_integer_limit+0x103/0x130 Read of…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.0

CVSS3.1

CVE-2025-39978 - octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node" and then dereferences it on the next line. Two lines later, we take a mutex so I don't th…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.0

CVSS3.1

CVE-2025-39984 - net: tun: Update napi->skb after XDP process

In the Linux kernel, the following vulnerability has been resolved: net: tun: Update napi->skb after XDP process The syzbot report a UAF issue: BUG: KASAN: slab-use-after-free in skb_reset_mac_header include/linux/skbuff.h:3150 [inline] BUG: KASAN: slab-use-after-free in napi_frags_skb net/c…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:26 p.m.

5.5

CVSS3.1

CVE-2025-39986 - can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow

In the Linux kernel, the following vulnerability has been resolved: can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow Sending an PF_PACKET allows to bypass the CAN framework logic and to directly reach the xmit() function of a CAN driver. The only check which is performed by th…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.
Total resulsts: 343040
Page 2803 of 34,304
Β« previous page Β» next page
Filters