5.5

CVSS3.1

CVE-2025-39832 - net/mlx5: Fix lockdep assertion on sync reset unload event

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix lockdep assertion on sync reset unload event Fix lockdep assertion triggered during sync reset unload event. When the sync reset flow is initiated using the devlink reload fw_activate option, the PF already holds th…

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 7:16 p.m.

7.8

CVSS3.1

CVE-2025-39828 - atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control().

In the Linux kernel, the following vulnerability has been resolved: atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). syzbot reported the splat below. [0] When atmtcp_v_open() or atmtcp_v_close() is called via connect() or close(), atmtcp_send_control() is called to send an in-kerne…

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:32 p.m.

5.5

CVSS3.1

CVE-2025-39827 - net: rose: include node references in rose_neigh refcount

In the Linux kernel, the following vulnerability has been resolved: net: rose: include node references in rose_neigh refcount Current implementation maintains two separate reference counting mechanisms: the 'count' field in struct rose_neigh tracks references from rose_node structures, while the …

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:35 p.m.

4.7

CVSS3.1

CVE-2025-39825 - smb: client: fix race with concurrent opens in rename(2)

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix race with concurrent opens in rename(2) Besides sending the rename request to the server, the rename process also involves closing any deferred close, waiting for outstanding I/O to complete as well as marking al…

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:37 p.m.

7.8

CVSS3.1

CVE-2025-39823 - KVM: x86: use array_index_nospec with indices that come from guest

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: use array_index_nospec with indices that come from guest min and dest_id are guest-controlled indices. Using array_index_nospec() after the bounds checks clamps these values to mitigate speculative execution side-channe…

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:38 p.m.

5.5

CVSS3.1

CVE-2025-39812 - sctp: initialize more fields in sctp_v6_from_sk()

In the Linux kernel, the following vulnerability has been resolved: sctp: initialize more fields in sctp_v6_from_sk() syzbot found that sin6_scope_id was not properly initialized, leading to undefined behavior. Clear sin6_scope_id and sin6_flowinfo. BUG: KMSAN: uninit-value in __sctp_v6_cmp_add…

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:08 p.m.

5.5

CVSS3.1

CVE-2025-39808 - HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version()

In the Linux kernel, the following vulnerability has been resolved: HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() in ntrig_report_version(), hdev parameter passed from hid_probe(). sending descriptor to /dev/uhid can make hdev->dev.parent->parent to null if hdev->dev.p…

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:07 p.m.

7.5

CVSS3.1

CVE-2025-56562 -

An incorrect API discovered in Signify Wiz Connected 1.9.1 allows attackers to remotely launch a DoS on Wiz devices only requiring the MAC address.

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 7:14 p.m.

7.5

CVSS3.1

CVE-2025-56264 -

The /api/comment endpoint in zhangyd-c OneBlog 2.3.9 contains a denial-of-service vulnerability.

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Sept. 23, 2025, 4:44 p.m.

5.5

CVSS3.1

CVE-2023-53284 - drm/msm/dpu: check for null return of devm_kzalloc() in dpu_writeback_init()

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: check for null return of devm_kzalloc() in dpu_writeback_init() Because of the possilble failure of devm_kzalloc(), dpu_wb_conn might be NULL and will cause null pointer dereference later. Therefore, it might be bet…

πŸ“… Published: Sept. 16, 2025, midnight πŸ”„ Last Modified: Jan. 14, 2026, 7:16 p.m.
Total resulsts: 349182
Page 3841 of 34,919
Β« previous page Β» next page
Filters