4.7

CVSS3.1

CVE-2025-38687 - comedi: fix race between polling and detaching

In the Linux kernel, the following vulnerability has been resolved: comedi: fix race between polling and detaching syzbot reports a use-after-free in comedi in the below link, which is due to comedi gladly removing the allocated async area even though poll requests are still active on the wait_qu…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 7 p.m.

5.5

CVSS3.1

CVE-2025-38727 - netlink: avoid infinite retry looping in netlink_unicast()

In the Linux kernel, the following vulnerability has been resolved: netlink: avoid infinite retry looping in netlink_unicast() netlink_attachskb() checks for the socket's read memory allocation constraints. Firstly, it has: rmem < READ_ONCE(sk->sk_rcvbuf) to check if the just increased rmem v…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:34 p.m.

7.8

CVSS3.1

CVE-2025-38697 - jfs: upper bound check of tree index in dbAllocAG

In the Linux kernel, the following vulnerability has been resolved: jfs: upper bound check of tree index in dbAllocAG When computing the tree index in dbAllocAG, we never check if we are out of bounds realative to the size of the stree. This could happen in a scenario where the filesystem metadat…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:11 p.m.

7.8

CVSS3.1

CVE-2025-38729 - ALSA: usb-audio: Validate UAC3 power domain descriptors, too

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 5:31 p.m.

7.8

CVSS3.1

CVE-2025-38722 - habanalabs: fix UAF in export_dmabuf()

In the Linux kernel, the following vulnerability has been resolved: habanalabs: fix UAF in export_dmabuf() As soon as we'd inserted a file reference into descriptor table, another thread could close it. That's fine for the case when all we are doing is returning that descriptor to userland (it's…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 9:47 p.m.

4.7

CVSS3.1

CVE-2025-38717 - net: kcm: Fix race condition in kcm_unattach()

In the Linux kernel, the following vulnerability has been resolved: net: kcm: Fix race condition in kcm_unattach() syzbot found a race condition when kcm_unattach(psock) and kcm_release(kcm) are executed at the same time. kcm_unattach() is missing a check of the flag kcm->tx_stopped before calli…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 10:07 p.m.

7.1

CVSS3.1

CVE-2025-38713 - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() The hfsplus_readdir() method is capable to crash by calling hfsplus_uni2asc(): [ 667.121659][ T9805] ================================================================== […

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:20 p.m.

5.5

CVSS3.1

CVE-2025-38712 - hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file()

In the Linux kernel, the following vulnerability has been resolved: hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() When the volume header contains erroneous values that do not reflect the actual state of the filesystem, hfsplus_fill_super() assumes that the attributes file is not…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:15 p.m.

5.5

CVSS3.1

CVE-2025-38706 - ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime()

In the Linux kernel, the following vulnerability has been resolved: ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() snd_soc_remove_pcm_runtime() might be called with rtd == NULL which will leads to null pointer dereference. This was reproduced with topology loading and marking a…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 8:32 p.m.

7.8

CVSS3.1

CVE-2025-38702 - fbdev: fix potential buffer overflow in do_register_framebuffer()

In the Linux kernel, the following vulnerability has been resolved: fbdev: fix potential buffer overflow in do_register_framebuffer() The current implementation may lead to buffer overflow when: 1. Unregistration creates NULL gaps in registered_fb[] 2. All array slots become occupied despite nu…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 8:31 p.m.
Total resulsts: 349182
Page 4025 of 34,919
Β« previous page Β» next page
Filters