7.1

CVSS3.1

CVE-2025-38636 - rv: Use strings in da monitors tracepoints

In the Linux kernel, the following vulnerability has been resolved: rv: Use strings in da monitors tracepoints Using DA monitors tracepoints with KASAN enabled triggers the following warning: BUG: KASAN: global-out-of-bounds in do_trace_event_raw_event_event_da_monitor+0xd6/0x1a0 Read of size …

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:12 p.m.

5.5

CVSS3.1

CVE-2025-38633 - clk: spacemit: mark K1 pll1_d8 as critical

In the Linux kernel, the following vulnerability has been resolved: clk: spacemit: mark K1 pll1_d8 as critical The pll1_d8 clock is enabled by the boot loader, and is ultimately a parent for numerous clocks, including those used by APB and AXI buses. Guodong Xu discovered that this clock got disa…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:11 p.m.

4.7

CVSS3.1

CVE-2025-38632 - pinmux: fix race causing mux_owner NULL with active mux_usecount

In the Linux kernel, the following vulnerability has been resolved: pinmux: fix race causing mux_owner NULL with active mux_usecount commit 5a3e85c3c397 ("pinmux: Use sequential access to access desc->pinmux data") tried to address the issue when two client of the same gpio calls pinctrl_select_s…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:11 p.m.

7.8

CVSS3.1

CVE-2025-38627 - f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix UAF of f2fs_inode_info in f2fs_free_dic The decompress_io_ctx may be released asynchronously after I/O completion. If this file is deleted immediately after read, and the kworker of processing post_read_wq has…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: March 25, 2026, 11:16 a.m.

5.5

CVSS3.1

CVE-2025-38625 - vfio/pds: Fix missing detach_ioas op

In the Linux kernel, the following vulnerability has been resolved: vfio/pds: Fix missing detach_ioas op When CONFIG_IOMMUFD is enabled and a device is bound to the pds_vfio_pci driver, the following WARN_ON() trace is seen and probe fails: WARNING: CPU: 0 PID: 5040 at drivers/vfio/vfio_main.c:3…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:05 p.m.

7.8

CVSS3.1

CVE-2025-38620 - zloop: fix KASAN use-after-free of tag set

In the Linux kernel, the following vulnerability has been resolved: zloop: fix KASAN use-after-free of tag set When a zoned loop device, or zloop device, is removed, KASAN enabled kernel reports "BUG KASAN use-after-free" in blk_mq_free_tag_set(). The BUG happens because zloop_ctl_remove() calls …

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:45 p.m.

7.8

CVSS3.1

CVE-2025-38618 - vsock: Do not allow binding to VMADDR_PORT_ANY

In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to autobind to VMADDR_PORT_ANY. This can cause a use-after-free when a connection is made to the bound socket. The socket returned by accept() also has por…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:56 p.m.

4.7

CVSS3.1

CVE-2025-38617 - net/packet: fix a race in packet_set_ring() and packet_notifier()

In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and packet_notifier() When packet_set_ring() releases po->bind_lock, another thread can run packet_notifier() and process an NETDEV_UP event. This race and the fix are both similar to …

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: March 18, 2026, 5:16 p.m.

5.5

CVSS3.1

CVE-2024-58239 - tls: stop recv() if initial process_rx_list gave us non-DATA

In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA …

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:42 p.m.

9.8

CVSS3.1

CVE-2022-43110 -

Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/cha…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4173 of 34,919
Β« previous page Β» next page
Filters