0.0

CVE-2025-40285 - smb/server: fix possible refcount leak in smb2_sess_setup()

In the Linux kernel, the following vulnerability has been resolved: smb/server: fix possible refcount leak in smb2_sess_setup() Reference count of ksmbd_session will leak when session need reconnect. Fix this by adding the missing ksmbd_user_session_put().

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40284 - Bluetooth: MGMT: cancel mesh send timer when hdev removed

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: cancel mesh send timer when hdev removed mesh_send_done timer is not canceled when hdev is removed, which causes crash if the timer triggers after hdev is gone. Cancel the timer when MGMT removes the hdev, like …

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40283 - Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF There is a KASAN: slab-use-after-free read in btusb_disconnect(). Calling "usb_driver_release_interface(&btusb_driver, data->intf)" will free the btusb data assoc…

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40282 - Bluetooth: 6lowpan: reset link-local header on ipv6 recv path

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: reset link-local header on ipv6 recv path Bluetooth 6lowpan.c netdev has header_ops, so it must set link-local header for RX skb, otherwise things crash, eg. with AF_PACKET SOCK_RAW Add missing skb_reset_mac_…

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40281 - sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto

In the Linux kernel, the following vulnerability has been resolved: sctp: prevent possible shift-out-of-bounds in sctp_transport_update_rto syzbot reported a possible shift-out-of-bounds [1] Blamed commit added rto_alpha_max and rto_beta_max set to 1000. It is unclear if some sctp users are set…

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40280 - tipc: Fix use-after-free in tipc_mon_reinit_self().

In the Linux kernel, the following vulnerability has been resolved: tipc: Fix use-after-free in tipc_mon_reinit_self(). syzbot reported use-after-free of tipc_net(net)->monitors[] in tipc_mon_reinit_self(). [0] The array is protected by RTNL, but tipc_mon_reinit_self() iterates over it without R…

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40279 - net: sched: act_connmark: initialize struct tc_ife to fix kernel leak

In the Linux kernel, the following vulnerability has been resolved: net: sched: act_connmark: initialize struct tc_ife to fix kernel leak In tcf_connmark_dump(), the variable 'opt' was partially initialized using a designatied initializer. While the padding bytes are reamined uninitialized. nla_p…

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40278 - net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak

In the Linux kernel, the following vulnerability has been resolved: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak Fix a KMSAN kernel-infoleak detected by the syzbot . [net?] KMSAN: kernel-infoleak in __skb_datagram_iter In tcf_ife_dump(), the variable 'opt' was par…

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40277 - drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.

πŸ“… Published: Dec. 6, 2025, 9:51 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.

0.0

CVE-2025-40276 - drm/panthor: Flush shmem writes before mapping buffers CPU-uncached

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Flush shmem writes before mapping buffers CPU-uncached The shmem layer zeroes out the new pages using cached mappings, and if we don't CPU-flush we might leave dirty cachelines behind, leading to potential data leaks…

πŸ“… Published: Dec. 6, 2025, 9:50 p.m. πŸ”„ Last Modified: Dec. 6, 2025, 10:15 p.m.
Total resulsts: 320463
Page 3 of 32,047
Β« previous page Β» next page
Filters