6.1

CVSS3.1

CVE-2025-5417 - Rhdh: red hat developer hub user permissions

An insufficient access control vulnerability was found in the Red Hat Developer Hub rhdh/rhdh-hub-rhel9 container image. The Red Hat Developer Hub cluster admin/user, who has standard user access to the cluster, and the Red Hat Developer Hub namespace, can access the rhdh/rhdh-hub-rhel9 container i…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-38582 - RDMA/hns: Fix double destruction of rsv_qp

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix double destruction of rsv_qp rsv_qp may be double destroyed in error flow, first in free_mr_init(), and then in hns_roce_exit(). Fix it by moving the free_mr_init() call into hns_roce_v2_init(). list_del corruption…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 7:58 p.m.

7.8

CVSS3.1

CVE-2025-38555 - usb: gadget : fix use-after-free in composite_dev_cleanup()

In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_cleanup() 1. In func configfs_composite_bind() -> composite_os_desc_req_prepare(): if kmalloc fails, the pointer cdev->os_desc_req will be freed but not set to NULL. Then it will …

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 8:49 p.m.

5.5

CVSS3.1

CVE-2025-38600 - wifi: mt76: mt7925: fix off by one in mt7925_mcu_hw_scan()

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix off by one in mt7925_mcu_hw_scan() The ssid->ssids[] and sreq->ssids[] arrays have MT7925_RNR_SCAN_MAX_BSSIDS elements so this >= needs to be > to prevent an out of bounds access.

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 6:01 p.m.

5.5

CVSS3.1

CVE-2025-38591 - bpf: Reject narrower access to pointer ctx fields

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject narrower access to pointer ctx fields The following BPF program, simplified from a syzkaller repro, causes a kernel warning: r0 = *(u8 *)(r1 + 169); exit; With pointer field sk being at offset 168 in __sk_bu…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:09 p.m.

9.8

CVSS3.1

CVE-2025-51543 -

An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_password endpoint.

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38576 - powerpc/eeh: Make EEH driver device hotplug safe

In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: Make EEH driver device hotplug safe Multiple race conditions existed between the PCIe hotplug driver and the EEH driver, leading to a variety of kernel oopses of the same general nature: <pcie device unplug> <eeh dr…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:15 p.m.

7.8

CVSS3.1

CVE-2025-38563 - perf/core: Prevent VMA split of buffer mappings

In the Linux kernel, the following vulnerability has been resolved: perf/core: Prevent VMA split of buffer mappings The perf mmap code is careful about mmap()'ing the user page with the ringbuffer and additionally the auxiliary buffer, when the event supports it. Once the first mapping is establi…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 9:03 p.m.

5.3

CVSS3.1

CVE-2025-51529 -

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unlimited database write operations to the wp_ajax_nopriv_cacsp_i…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Oct. 21, 2025, 2:25 p.m.

5.5

CVSS3.1

CVE-2025-38577 - f2fs: fix to avoid panic in f2fs_evict_inode

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid panic in f2fs_evict_inode As syzbot [1] reported as below: R10: 0000000000000100 R11: 0000000000000206 R12: 00007ffe17473450 R13: 00007f28b1c10854 R14: 000000000000dae5 R15: 00007ffe17474520 </TASK> ---[ end …

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:15 p.m.
Total resulsts: 349182
Page 4229 of 34,919
Β« previous page Β» next page
Filters