5.5

CVSS3.1

CVE-2022-50428 - ext4: fix off-by-one errors in fast-commit block filling

In the Linux kernel, the following vulnerability has been resolved: ext4: fix off-by-one errors in fast-commit block filling Due to several different off-by-one errors, or perhaps due to a late change in design that wasn't fully reflected in the code that was actually merged, there are several ve…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 20, 2026, 3:37 p.m.

5.5

CVSS3.1

CVE-2023-53483 - ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup()

In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Check for null return of devm_kzalloc() in fch_misc_setup() devm_kzalloc() may fail, clk_data->name might be NULL and will cause a NULL pointer dereference later. [ rjw: Subject and changelog edits ]

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 2:07 a.m.

5.5

CVSS3.1

CVE-2023-53467 - wifi: rtw89: fix potential leak in rtw89_append_probe_req_ie()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix potential leak in rtw89_append_probe_req_ie() Do `kfree_skb(new)` before `goto out` to prevent potential leak.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 20, 2026, 3:53 p.m.

4.7

CVSS3.1

CVE-2023-53520 - Bluetooth: Fix hci_suspend_sync crash

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix hci_suspend_sync crash If hci_unregister_dev() frees the hci_dev object but hci_suspend_notifier may still be accessing it, it can cause the program to crash. Here's the call trace: <4>[102152.653246] Call Trace:…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: April 6, 2026, 1:13 p.m.

8.2

CVSS3.1

CVE-2025-52042 -

In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vulnerable to SQL Injection, which allows an attacker to extract all information from databases by injecting SQL query via the txt parameter.

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 4:19 p.m.

5.5

CVSS3.1

CVE-2025-39928 - i2c: rtl9300: ensure data length is within supported range

In the Linux kernel, the following vulnerability has been resolved: i2c: rtl9300: ensure data length is within supported range Add an explicit check for the xfer length to 'rtl9300_i2c_config_xfer' to ensure the data length isn't within the supported range. In particular a data length of 0 is not…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 6:16 p.m.

7.8

CVSS3.1

CVE-2025-39896 - accel/ivpu: Prevent recovery work from being queued during device removal

In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Prevent recovery work from being queued during device removal Use disable_work_sync() instead of cancel_work_sync() in ivpu_dev_fini() to ensure that no new recovery work items can be queued after device removal has s…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

5.5

CVSS3.1

CVE-2025-39903 - of_numa: fix uninitialized memory nodes causing kernel panic

In the Linux kernel, the following vulnerability has been resolved: of_numa: fix uninitialized memory nodes causing kernel panic When there are memory-only nodes (nodes without CPUs), these nodes are not properly initialized, causing kernel panic during boot. of_numa_init of_numa_parse_cpu_node…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:16 p.m.

7.0

CVSS3.1

CVE-2023-53469 - af_unix: Fix null-ptr-deref in unix_stream_sendpage().

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix null-ptr-deref in unix_stream_sendpage(). Bing-Jhong Billy Jheng reported null-ptr-deref in unix_stream_sendpage() with detailed analysis and a nice repro. unix_stream_sendpage() tries to add data to the last skb in…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:15 p.m.

5.5

CVSS3.1

CVE-2023-53509 - qed: allow sleep in qed_mcp_trace_dump()

In the Linux kernel, the following vulnerability has been resolved: qed: allow sleep in qed_mcp_trace_dump() By default, qed_mcp_cmd_and_union() delays 10us at a time in a loop that can run 500K times, so calls to qed_mcp_nvm_rd_cmd() may block the current thread for over 5s. We observed thread s…

πŸ“… Published: Oct. 1, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 1:58 a.m.
Total resulsts: 349182
Page 3613 of 34,919
Β« previous page Β» next page
Filters