0.0

CVE-2025-68285 - libceph: fix potential use-after-free in have_mon_and_osd_map()

In the Linux kernel, the following vulnerability has been resolved: libceph: fix potential use-after-free in have_mon_and_osd_map() The wait loop in __ceph_open_session() can race with the client receiving a new monmap or osdmap shortly after the initial map is received. Both ceph_monc_handle_ma…

πŸ“… Published: Dec. 16, 2025, 3:06 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:06 p.m.

0.0

CVE-2025-68284 - libceph: prevent potential out-of-bounds writes in handle_auth_session_key()

In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() The len field originates from untrusted network packets. Boundary checks have been added to prevent potential out-of-bounds writes when decrypting the c…

πŸ“… Published: Dec. 16, 2025, 3:06 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:06 p.m.

0.0

CVE-2025-68283 - libceph: replace BUG_ON with bounds check for map->max_osd

In the Linux kernel, the following vulnerability has been resolved: libceph: replace BUG_ON with bounds check for map->max_osd OSD indexes come from untrusted network packets. Boundary checks are added to validate these against map->max_osd. [ idryomov: drop BUG_ON in ceph_get_primary_affinity()…

πŸ“… Published: Dec. 16, 2025, 3:06 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:06 p.m.

0.0

CVE-2025-68282 - usb: gadget: udc: fix use-after-free in usb_gadget_state_work

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: fix use-after-free in usb_gadget_state_work A race condition during gadget teardown can lead to a use-after-free in usb_gadget_state_work(), as reported by KASAN: BUG: KASAN: invalid-access in sysfs_notify+0x…

πŸ“… Published: Dec. 16, 2025, 3:06 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 3:06 p.m.

0.0

CVE-2025-68281 - ASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list

In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: bug fix while parsing mipi-sdca-control-cn-list "struct sdca_control" declares "values" field as integer array. But the memory allocated to it is of char array. This causes crash for sdca_parse_function API. This patc…

πŸ“… Published: Dec. 16, 2025, 2:48 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:48 p.m.

0.0

CVE-2025-68266 - bfs: Reconstruct file type when loading from disk

In the Linux kernel, the following vulnerability has been resolved: bfs: Reconstruct file type when loading from disk syzbot is reporting that S_IFMT bits of inode->i_mode can become bogus when the S_IFMT bits of the 32bits "mode" field loaded from disk are corrupted or when the 32bits "attribute…

πŸ“… Published: Dec. 16, 2025, 2:47 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:47 p.m.

0.0

CVE-2025-68265 - nvme: fix admin request_queue lifetime

In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin request_queue lifetime The namespaces can access the controller's admin request_queue, and stale references on the namespaces may exist after tearing down the controller. Ensure the admin request_queue is active b…

πŸ“… Published: Dec. 16, 2025, 2:47 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:47 p.m.

0.0

CVE-2025-68264 - ext4: refresh inline data size before write operations

In the Linux kernel, the following vulnerability has been resolved: ext4: refresh inline data size before write operations The cached ei->i_inline_size can become stale between the initial size check and when ext4_update_inline_data()/ext4_create_inline_data() use it. Although ext4_get_max_inline…

πŸ“… Published: Dec. 16, 2025, 2:45 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:45 p.m.

0.0

CVE-2025-68263 - ksmbd: ipc: fix use-after-free in ipc_msg_send_request

In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() waits for a generic netlink reply using an ipc_msg_table_entry on the stack. The generic netlink handler (handle_generic_event()/handle_response()) fil…

πŸ“… Published: Dec. 16, 2025, 2:45 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:45 p.m.

0.0

CVE-2025-68262 - crypto: zstd - fix double-free in per-CPU stream cleanup

In the Linux kernel, the following vulnerability has been resolved: crypto: zstd - fix double-free in per-CPU stream cleanup The crypto/zstd module has a double-free bug that occurs when multiple tfms are allocated and freed. The issue happens because zstd_streams (per-CPU contexts) are freed in…

πŸ“… Published: Dec. 16, 2025, 2:45 p.m. πŸ”„ Last Modified: Dec. 16, 2025, 2:45 p.m.
Total resulsts: 322969
Page 29 of 32,297
Β« previous page Β» next page
Filters