5.5

CVSS3.1

CVE-2023-53421 - blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats()

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats() When blkg_alloc() is called to allocate a blkcg_gq structure with the associated blkg_iostat_set's, there are 2 fields within blkg_iostat_set that requires …

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: April 6, 2026, 2 p.m.

5.5

CVSS3.1

CVE-2023-53396 - ubifs: Fix memory leak in do_rename

In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix memory leak in do_rename If renaming a file in an encrypted directory, function fscrypt_setup_filename allocates memory for a file name. This name is never used, and before returning to the caller the memory for it is …

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 7:16 p.m.

7.1

CVSS3.1

CVE-2023-53376 - scsi: mpi3mr: Use number of bits to manage bitmap sizes

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Use number of bits to manage bitmap sizes To allocate bitmaps, the mpi3mr driver calculates sizes of bitmaps using byte as unit. However, bitmap helper functions assume that bitmaps are allocated using unsigned long…

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 7:16 p.m.

5.5

CVSS3.1

CVE-2022-50405 - net/tunnel: wait until all sk_user_data reader finish before releasing the sock

In the Linux kernel, the following vulnerability has been resolved: net/tunnel: wait until all sk_user_data reader finish before releasing the sock There is a race condition in vxlan that when deleting a vxlan device during receiving packets, there is a possibility that the sock is released after…

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 8:15 p.m.

8.8

CVSS3.1

CVE-2025-57293 -

A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt. The phy_interface parameter is not sanitized, allowing attackers to inject arbitrary commands via a POST request to /cgi-bin/mbox-config?me…

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: Oct. 3, 2025, 5:24 p.m.

6.5

CVSS3.1

CVE-2025-55911 -

An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 5:13 p.m.

5.5

CVSS3.1

CVE-2022-50383 - media: mediatek: vcodec: Can't set dst buffer to done when lat decode error

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Can't set dst buffer to done when lat decode error Core thread will call v4l2_m2m_buf_done to set dst buffer done for lat architecture. If lat call v4l2_m2m_buf_done_and_job_finish to free dst buffer when…

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: Jan. 26, 2026, 4:17 p.m.

7.1

CVSS3.1

CVE-2022-50394 - i2c: ismt: Fix an out-of-bounds bug in ismt_access()

In the Linux kernel, the following vulnerability has been resolved: i2c: ismt: Fix an out-of-bounds bug in ismt_access() When the driver does not check the data from the user, the variable 'data->block[0]' may be very large to cause an out-of-bounds bug. The following log can reveal it: [ 33.…

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 7:16 p.m.

5.5

CVSS3.1

CVE-2022-50400 - staging: greybus: audio_helper: remove unused and wrong debugfs usage

In the Linux kernel, the following vulnerability has been resolved: staging: greybus: audio_helper: remove unused and wrong debugfs usage In the greybus audio_helper code, the debugfs file for the dapm has the potential to be removed and memory will be leaked. There is also the very real potenti…

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 7:16 p.m.

3.7

CVSS3.1

CVE-2025-59691 -

PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or system resume. In the CLI client, the VPN auto-reconnects and claims to be connected, but IPv6 traffic is no longer routed or blocked. In the …

πŸ“… Published: Sept. 18, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3793 of 34,919
Β« previous page Β» next page
Filters