5.5

CVSS3.1

CVE-2025-38701 - ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr

In the Linux kernel, the following vulnerability has been resolved: ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr A syzbot fuzzed image triggered a BUG_ON in ext4_update_inline_data() when an inode had the INLINE_DATA_FL flag set but was missing the system.data extended attribute. …

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 4:18 p.m.

7.8

CVSS3.1

CVE-2025-38699 - scsi: bfa: Double-free fix

In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Double-free fix When the bfad_im_probe() function fails during initialization, the memory pointed to by bfad->im is freed without setting bfad->im to NULL. Subsequently, during driver uninstallation, when the state ma…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9:52 p.m.

5.5

CVSS3.1

CVE-2025-38698 - jfs: Regular file corruption check

In the Linux kernel, the following vulnerability has been resolved: jfs: Regular file corruption check The reproducer builds a corrupted file on disk with a negative i_size value. Add a check when opening this file to avoid subsequent operation failures.

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:15 p.m.

5.5

CVSS3.1

CVE-2025-38692 - exfat: add cluster chain loop check for dir

In the Linux kernel, the following vulnerability has been resolved: exfat: add cluster chain loop check for dir An infinite loop may occur if the following conditions occur due to file system corruption. (1) Condition for exfat_count_dir_entries() to loop infinitely. - The cluster chain incl…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 7:45 p.m.

7.8

CVSS3.1

CVE-2025-38688 - iommufd: Prevent ALIGN() overflow

In the Linux kernel, the following vulnerability has been resolved: iommufd: Prevent ALIGN() overflow When allocating IOVA the candidate range gets aligned to the target alignment. If the range is close to ULONG_MAX then the ALIGN() can wrap resulting in a corrupted iova. Open code the ALIGN() u…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 7:47 p.m.

7.8

CVSS3.1

CVE-2025-38682 - i2c: core: Fix double-free of fwnode in i2c_unregister_device()

In the Linux kernel, the following vulnerability has been resolved: i2c: core: Fix double-free of fwnode in i2c_unregister_device() Before commit df6d7277e552 ("i2c: core: Do not dereference fwnode in struct device"), i2c_unregister_device() only called fwnode_handle_put() on of_node-s in the for…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 10:06 p.m.

4.7

CVSS3.1

CVE-2025-38681 - mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd()

In the Linux kernel, the following vulnerability has been resolved: mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() Memory hot remove unmaps and tears down various kernel page table regions as required. The ptdump code can race with concurrent modifications of the kernel page ta…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 10:32 p.m.

5.5

CVSS3.1

CVE-2025-38726 - net: ftgmac100: fix potential NULL pointer access in ftgmac100_phy_disconnect

In the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix potential NULL pointer access in ftgmac100_phy_disconnect After the call to phy_disconnect() netdev->phydev is reset to NULL. So fixed_phy_unregister() would be called with a NULL pointer as argument. Therefor…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 9:50 p.m.

5.5

CVSS3.1

CVE-2025-38700 - scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated

In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated In case of an ib_fast_reg_mr allocation failure during iSER setup, the machine hits a panic because iscsi_conn->dd_data is initialized unconditionally, ev…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 5:04 p.m.

5.5

CVSS3.1

CVE-2025-38684 - net/sched: ets: use old 'nbands' while purging unused classes

In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: use old 'nbands' while purging unused classes Shuang reported sch_ets test-case [1] crashing in ets_class_qlen_notify() after recent changes from Lion [2]. The problem is: in ets_qdisc_change() we purge unused DWR…

πŸ“… Published: Sept. 4, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 10:32 p.m.
Total resulsts: 349182
Page 4026 of 34,919
Β« previous page Β» next page
Filters