5.5

CVSS3.1

CVE-2025-38660 - [ceph] parse_longname(): strrchr() expects NUL-terminated string

In the Linux kernel, the following vulnerability has been resolved: [ceph] parse_longname(): strrchr() expects NUL-terminated string ... and parse_longname() is not guaranteed that. That's the reason why it uses kmemdup_nul() to build the argument for kstrtou64(); the problem is, kstrtou64() is …

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 25, 2025, 10:13 p.m.

5.5

CVSS3.1

CVE-2025-38658 - nvmet: pci-epf: Do not complete commands twice if nvmet_req_init() fails

In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: Do not complete commands twice if nvmet_req_init() fails Have nvmet_req_init() and req->execute() complete failed commands. Description of the problem: nvmet_req_init() calls __nvmet_req_complete() internally upo…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 4:32 p.m.

5.5

CVSS3.1

CVE-2025-38654 - pinctrl: canaan: k230: Fix order of DT parse and pinctrl register

In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix order of DT parse and pinctrl register Move DT parse before pinctrl register. This ensures that device tree parsing is done before calling devm_pinctrl_register() to prevent using uninitialized pin reso…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 4:32 p.m.

7.8

CVSS3.1

CVE-2025-38653 - proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al

In the Linux kernel, the following vulnerability has been resolved: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al Check pde->proc_ops->proc_lseek directly may cause UAF in rmmod scenario. It's a gap in proc_reg_open() after commit 654b33ada4ab("proc: fix UAF i…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 5:36 p.m.

7.1

CVSS3.1

CVE-2025-38652 - f2fs: fix to avoid out-of-boundary access in devs.path

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.path - touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/01234567890123456789012345678901234567890123456789012…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 5:36 p.m.

5.5

CVSS3.1

CVE-2025-38649 - arm64: dts: qcom: qcs615: fix a crash issue caused by infinite loop for Coresight

In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: qcs615: fix a crash issue caused by infinite loop for Coresight An infinite loop has been created by the Coresight devices. When only a source device is enabled, the coresight_find_activated_sysfs_sink function …

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 4:27 p.m.

5.5

CVSS3.1

CVE-2025-38648 - spi: stm32: Check for cfg availability in stm32_spi_probe

In the Linux kernel, the following vulnerability has been resolved: spi: stm32: Check for cfg availability in stm32_spi_probe The stm32_spi_probe function now includes a check to ensure that the pointer returned by of_device_get_match_data is not NULL before accessing its members. This resolves a…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 4:27 p.m.

5.5

CVSS3.1

CVE-2025-38647 - wifi: rtw89: sar: drop lockdep assertion in rtw89_set_sar_from_acpi

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: sar: drop lockdep assertion in rtw89_set_sar_from_acpi The following assertion is triggered on the rtw89 driver startup. It looks meaningless to hold wiphy lock on the early init stage so drop the assertion. WARNIN…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Dec. 15, 2025, 10:54 p.m.

5.5

CVSS3.1

CVE-2025-38645 - net/mlx5: Check device memory pointer before usage

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Check device memory pointer before usage Add a NULL check before accessing device memory to prevent a crash if dev->dm allocation in mlx5_init_once() fails.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 5:36 p.m.

5.5

CVSS3.1

CVE-2025-38639 - netfilter: xt_nfacct: don't assume acct name is null-terminated

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nfacct: don't assume acct name is null-terminated BUG: KASAN: slab-out-of-bounds in .. lib/vsprintf.c:721 Read of size 1 at addr ffff88801eac95c8 by task syz-executor183/5851 [..] string+0x231/0x2b0 lib/vsprintf.c:…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:25 p.m.
Total resulsts: 349182
Page 4172 of 34,919
Β« previous page Β» next page
Filters