7.8

CVSS3.1

CVE-2025-38707 - fs/ntfs3: Add sanity check for file name

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add sanity check for file name The length of the file name should be smaller than the directory entry size.

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 4:12 p.m.

7.1

CVSS3.1

CVE-2025-38680 - media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format()

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() The buffer length check before calling uvc_parse_format() only ensured that the buffer has at least 3 bytes (buflen > 2), buf the function accesses buffer[3], r…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 10:32 p.m.

5.5

CVSS3.1

CVE-2025-38690 - drm/xe/migrate: prevent infinite recursion

In the Linux kernel, the following vulnerability has been resolved: drm/xe/migrate: prevent infinite recursion If the buf + offset is not aligned to XE_CAHELINE_BYTES we fallback to using a bounce buffer. However the bounce buffer here is allocated on the stack, and the only alignment requirement…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 7:47 p.m.

5.5

CVSS3.1

CVE-2025-38723 - LoongArch: BPF: Fix jump offset calculation in tailcall

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix jump offset calculation in tailcall The extra pass of bpf_int_jit_compile() skips JIT context initialization which essentially skips offset calculation leaving out_offset = -1, so the jmp_offset in emit_bpf_ta…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:42 p.m.

7.8

CVSS3.1

CVE-2025-38685 - fbdev: Fix vmalloc out-of-bounds write in fast_imageblit

In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix vmalloc out-of-bounds write in fast_imageblit This issue triggers when a userspace program does an ioctl FBIOPUT_CON2FBMAP by passing console number and frame buffer number. Ideally this maps console to frame buffer an…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 10:31 p.m.

10

CVSS3.1

CVE-2025-55190 - Argo CD: Project API Token Exposes Repository Credentials

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 through 2.14.15, 3.0.0 through 3.0.12 and 3.1.0-rc1 through 3.1.1, API tokens with project-level permissions are able to retrieve sensitive repository credentials (usernames, password…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Sept. 19, 2025, 3:20 p.m.

7.8

CVSS3.1

CVE-2025-38704 - rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access

In the Linux kernel, the following vulnerability has been resolved: rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer access In the preparation stage of CPU online, if the corresponding the rdp's->nocb_cb_kthread does not exist, will be created, there is a situation where the rdp's rc…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: March 25, 2026, 11:16 a.m.

5.5

CVSS3.1

CVE-2025-38710 - gfs2: Validate i_depth for exhash directories

In the Linux kernel, the following vulnerability has been resolved: gfs2: Validate i_depth for exhash directories A fuzzer test introduced corruption that ends up with a depth of 0 in dir_e_read(), causing an undefined shift by 32 at: index = hash >> (32 - dip->i_depth); As calculated in an o…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 10 p.m.

7.8

CVSS3.1

CVE-2025-38718 - sctp: linearize cloned gso packets in sctp_rcv

In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A cloned head skb still shares these frag skbs in fraglist with the original head skb. It's not safe to access these frag skbs. syzbot reported two use-of-uninitialized-memory bugs …

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:21 p.m.

7.1

CVSS3.1

CVE-2025-38714 - hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read()

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() The hfsplus_bnode_read() method can trigger the issue: [ 174.852007][ T9784] ================================================================== [ 174.852709][ T9784] BUG:…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 4:09 p.m.
Total resulsts: 349182
Page 4022 of 34,919
Β« previous page Β» next page
Filters