7.0

CVSS3.1

CVE-2025-39968 - i40e: add max boundary check for VF filters

In the Linux kernel, the following vulnerability has been resolved: i40e: add max boundary check for VF filters There is no check for max filters that VF can request. Add it.

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:26 p.m.

7.0

CVSS3.1

CVE-2025-39994 - media: tuner: xc5000: Fix use-after-free in xc5000_release

In the Linux kernel, the following vulnerability has been resolved: media: tuner: xc5000: Fix use-after-free in xc5000_release The original code uses cancel_delayed_work() in xc5000_release(), which does not guarantee that the delayed work item timer_sleep has fully completed if it was already ru…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.0

CVSS3.1

CVE-2025-39991 - wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load()

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to data, then fw pointer remains null. Further, if m3_mem is not allocated, then fw is dereferenced to be passed to ath11k_err function. Replace…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.0

CVSS3.1

CVE-2025-39976 - futex: Use correct exit on failure from futex_hash_allocate_default()

In the Linux kernel, the following vulnerability has been resolved: futex: Use correct exit on failure from futex_hash_allocate_default() copy_process() uses the wrong error exit path from futex_hash_allocate_default(). After exiting from futex_hash_allocate_default(), neither tasklist_lock nor s…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 20, 2025, 1:27 p.m.

7.0

CVSS3.1

CVE-2025-40000 - wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait() There is a bug observed when rtw89_core_tx_kick_off_and_wait() tries to access already freed skb_data: BUG: KFENCE: use-after-free write in rtw89_core_tx_kick…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.0

CVSS3.1

CVE-2025-39993 - media: rc: fix races with imon_disconnect()

In the Linux kernel, the following vulnerability has been resolved: media: rc: fix races with imon_disconnect() Syzbot reports a KASAN issue as below: BUG: KASAN: use-after-free in __create_pipe include/linux/usb.h:1945 [inline] BUG: KASAN: use-after-free in send_packet+0xa2d/0xbc0 drivers/media/…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

5.5

CVSS3.1

CVE-2025-39995 - media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe

In the Linux kernel, the following vulnerability has been resolved: media: i2c: tc358743: Fix use-after-free bugs caused by orphan timer in probe The state->timer is a cyclic timer that schedules work_i2c_poll and delayed_work_enable_hotplug, while rearming itself. Using timer_delete() fails to g…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.0

CVSS3.1

CVE-2025-39992 - mm: swap: check for stable address space before operating on the VMA

In the Linux kernel, the following vulnerability has been resolved: mm: swap: check for stable address space before operating on the VMA It is possible to hit a zero entry while traversing the vmas in unuse_mm() called from swapoff path and accessing it causes the OOPS: Unable to handle kernel N…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Dec. 1, 2025, 6:16 a.m.

7.0

CVSS3.1

CVE-2025-39998 - scsi: target: target_core_configfs: Add length check to avoid buffer overflow

In the Linux kernel, the following vulnerability has been resolved: scsi: target: target_core_configfs: Add length check to avoid buffer overflow A buffer overflow arises from the usage of snprintf to write into the buffer "buf" in target_lu_gp_members_show function located in /drivers/target/tar…

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:32 p.m.

9.4

CVSS3.1

CVE-2025-56749 -

Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictable secret allows attackers to forge valid JWT tokens, leading to authentication bypass and unauthorized access to any user account.

πŸ“… Published: Oct. 15, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 7:24 p.m.
Total resulsts: 343054
Page 2804 of 34,306
Β« previous page Β» next page
Filters