5.5

CVSS3.1

CVE-2025-39914 - tracing: Silence warning when chunk allocation fails in trace_pid_write

In the Linux kernel, the following vulnerability has been resolved: tracing: Silence warning when chunk allocation fails in trace_pid_write Syzkaller trigger a fault injection warning: WARNING: CPU: 1 PID: 12326 at tracepoint_add_func+0xbfc/0xeb0 Modules linked in: CPU: 1 UID: 0 PID: 12326 Comm:…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:50 p.m.

7.8

CVSS3.1

CVE-2025-39913 - tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork.

In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork. syzbot reported the splat below. [0] The repro does the following: 1. Load a sk_msg prog that calls bpf_msg_cork_bytes(msg, cork_bytes) …

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 7:48 p.m.

5.5

CVSS3.1

CVE-2025-39910 - mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc()

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc, mm/kasan: respect gfp mask in kasan_populate_vmalloc() kasan_populate_vmalloc() and its helpers ignore the caller's gfp_mask and always allocate memory using the hardcoded GFP_KERNEL flag. This makes them inconsisten…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 6:16 p.m.

7.1

CVSS3.1

CVE-2025-39901 - i40e: remove read access to debugfs files

In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'command' and 'netdev_ops' debugfs files are a legacy debugging interface supported by the i40e driver since its early days by commit 02e9c290814c ("i40e: debugfs interface"). Both o…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

5.5

CVSS3.1

CVE-2025-39900 - net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y

In the Linux kernel, the following vulnerability has been resolved: net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y syzbot reported a WARNING in est_timer() [1] Problem here is that with CONFIG_PREEMPT_RT=y, timer callbacks can be preempted. Adopt preempt_disable_nested()/preem…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.8

CVSS3.1

CVE-2022-50422 - scsi: libsas: Fix use-after-free bug in smp_execute_task_sg()

In the Linux kernel, the following vulnerability has been resolved: scsi: libsas: Fix use-after-free bug in smp_execute_task_sg() When executing SMP task failed, the smp_execute_task_sg() calls del_timer() to delete "slow_task->timer". However, if the timer handler sas_task_internal_timedout() is…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 6:16 p.m.

5.5

CVSS3.1

CVE-2025-39923 - dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees

In the Linux kernel, the following vulnerability has been resolved: dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees When we don't have a clock specified in the device tree, we have no way to ensure the BAM is on. This is often the case for remotely-controlled or remotely-powe…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 20, 2026, 3:45 p.m.

4.7

CVSS3.1

CVE-2023-53490 - mptcp: fix disconnect vs accept race

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix disconnect vs accept race Despite commit 0ad529d9fd2b ("mptcp: fix possible divide by zero in recvmsg()"), the mptcp protocol is still prone to a race between disconnect() (or shutdown) and accept. The root cause is t…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:40 p.m.

7.1

CVSS3.1

CVE-2025-59681 - django: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL …

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a suitably crafted dictionary, with dictionary expansion, as the…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2024-57494 -

Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3607 of 34,919
Β« previous page Β» next page
Filters