5.5

CVSS3.1

CVE-2025-39779 - btrfs: subpage: keep TOWRITE tag until folio is cleaned

In the Linux kernel, the following vulnerability has been resolved: btrfs: subpage: keep TOWRITE tag until folio is cleaned btrfs_subpage_set_writeback() calls folio_start_writeback() the first time a folio is written back, and it also clears the PAGECACHE_TAG_TOWRITE tag even if there are still …

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 7:08 p.m.

7.8

CVSS3.1

CVE-2025-39776 - mm/debug_vm_pgtable: clear page table entries at destroy_args()

In the Linux kernel, the following vulnerability has been resolved: mm/debug_vm_pgtable: clear page table entries at destroy_args() The mm/debug_vm_pagetable test allocates manually page table entries for the tests it runs, using also its manually allocated mm_struct. That in itself is ok, but w…

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:12 p.m.

5.5

CVSS3.1

CVE-2025-39748 - bpf: Forget ranges when refining tnum after JSET

In the Linux kernel, the following vulnerability has been resolved: bpf: Forget ranges when refining tnum after JSET Syzbot reported a kernel warning due to a range invariant violation on the following BPF program. 0: call bpf_get_netns_cookie 1: if r0 == 0 goto <exit> 2: if r0 & Oxfffffff…

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 4:45 p.m.

7.8

CVSS3.1

CVE-2025-39743 - jfs: truncate good inode pages when hard link is 0

In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 The fileset value of the inode copy from the disk by the reproducer is AGGR_RESERVED_I. When executing evict, its hard link number is 0, so its inode pages are not truncated. Thi…

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 7:05 p.m.

5.5

CVSS3.1

CVE-2025-39782 - jbd2: prevent softlockup in jbd2_log_do_checkpoint()

In the Linux kernel, the following vulnerability has been resolved: jbd2: prevent softlockup in jbd2_log_do_checkpoint() Both jbd2_log_do_checkpoint() and jbd2_journal_shrink_checkpoint_list() periodically release j_list_lock after processing a batch of buffers to avoid long hold times on the j_l…

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:24 p.m.

3.8

CVSS3.1

CVE-2025-56556 -

An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool.

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-39736 - mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock

In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid deadlock by moving pr_warn() outside kmemleak_lock When netpoll is enabled, calling pr_warn_once() while holding kmemleak_lock in mem_pool_alloc() can cause a deadlock due to lock inversion with the netconsole …

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:59 p.m.

7.8

CVSS3.1

CVE-2025-39783 - PCI: endpoint: Fix configfs group list head handling

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Fix configfs group list head handling Doing a list_del() on the epf_group field of struct pci_epf_driver in pci_epf_remove_cfs() is not correct as this field is a list head, not a list entry. This list_del() call t…

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Jan. 16, 2026, 8:24 p.m.

5.5

CVSS3.1

CVE-2025-39741 - drm/xe/migrate: don't overflow max copy size

In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: don't overflow max copy size With non-page aligned copy, we need to use 4 byte aligned pitch, however the size itself might still be close to our maximum of ~8M, and so the dimensions of the copy can easily exceed…

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 9:08 p.m.

5.5

CVSS3.1

CVE-2025-39777 - crypto: acomp - Fix CFI failure due to type punning

In the Linux kernel, the following vulnerability has been resolved: crypto: acomp - Fix CFI failure due to type punning To avoid a crash when control flow integrity is enabled, make the workspace ("stream") free function use a consistent type, and call it through a function pointer that has that …

πŸ“… Published: Sept. 11, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 7:09 p.m.
Total resulsts: 349182
Page 3910 of 34,919
Β« previous page Β» next page
Filters