7.8

CVSS3.1

CVE-2023-53652 - vdpa: Add features attr to vdpa_nl_policy for nlattr length check

In the Linux kernel, the following vulnerability has been resolved: vdpa: Add features attr to vdpa_nl_policy for nlattr length check The vdpa_nl_policy structure is used to validate the nlattr when parsing the incoming nlmsg. It will ensure the attribute being described produces a valid nlattr p…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 3, 2026, 10:24 p.m.

5.5

CVSS3.1

CVE-2023-53617 - soc: aspeed: socinfo: Add kfree for kstrdup

In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: socinfo: Add kfree for kstrdup Add kfree() in the later error handling in order to avoid memory leak.

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3 p.m.

5.5

CVSS3.1

CVE-2022-50527 - drm/amdgpu: Fix size validation for non-exclusive domains (v4)

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix size validation for non-exclusive domains (v4) Fix amdgpu_bo_validate_size() to check whether the TTM domain manager for the requested memory exists, else we get a kernel oops when dereferencing "man". v2: Make t…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:53 p.m.

5.5

CVSS3.1

CVE-2023-53625 - drm/i915/gvt: fix vgpu debugfs clean in remove

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gvt: fix vgpu debugfs clean in remove Check carefully on root debugfs available when destroying vgpu, e.g in remove case drm minor's debugfs root might already be destroyed, which led to kernel oops like below. Console:…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 2:31 p.m.

5.5

CVSS3.1

CVE-2022-50544 - usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info()

In the Linux kernel, the following vulnerability has been resolved: usb: host: xhci: Fix potential memory leak in xhci_alloc_stream_info() xhci_alloc_stream_info() allocates stream context array for stream_info ->stream_ctx_array with xhci_alloc_stream_ctx(). When some error occurs, stream_info->…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 11:17 p.m.

5.5

CVSS3.1

CVE-2022-50555 - tipc: fix a null-ptr-deref in tipc_topsrv_accept

In the Linux kernel, the following vulnerability has been resolved: tipc: fix a null-ptr-deref in tipc_topsrv_accept syzbot found a crash in tipc_topsrv_accept: KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] Workqueue: tipc_rcv tipc_topsrv_accept RIP: 0010:kernel_ac…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:01 p.m.

5.5

CVSS3.1

CVE-2022-50553 - tracing/hist: Fix out-of-bound write on 'action_data.var_ref_idx'

In the Linux kernel, the following vulnerability has been resolved: tracing/hist: Fix out-of-bound write on 'action_data.var_ref_idx' When generate a synthetic event with many params and then create a trace action for it [1], kernel panic happened [2]. It is because that in trace_action_create()…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2026, 7:45 p.m.

7.8

CVSS3.1

CVE-2022-50546 - ext4: fix uninititialized value in 'ext4_evict_inode'

In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninititialized value in 'ext4_evict_inode' Syzbot found the following issue: ===================================================== BUG: KMSAN: uninit-value in ext4_evict_inode+0xdd/0x26b0 fs/ext4/inode.c:180 ext4_evic…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 11:17 p.m.

5.5

CVSS3.1

CVE-2022-50514 - usb: gadget: f_hid: fix refcount leak on error path

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_hid: fix refcount leak on error path When failing to allocate report_desc, opts->refcnt has already been incremented so it needs to be decremented to avoid leaving the options structure permanently locked.

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 2:11 p.m.

7.1

CVSS3.1

CVE-2025-6242 - Vllm: server side request forgery (ssrf) in mediaconnector

A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set. The load_from_url and load_from_url_async methods fetch and process media from user-provided URLs without adequate restrictions on the target hosts. This allows an…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3531 of 34,919
Β« previous page Β» next page
Filters