7.8

CVSS3.1

CVE-2025-38579 - f2fs: fix KMSAN uninit-value in extent_info usage

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix KMSAN uninit-value in extent_info usage KMSAN reported a use of uninitialized value in `__is_extent_mergeable()` and `__is_back_mergeable()` via the read extent tree path. The root cause is that `get_read_extent_info(…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 1:57 p.m.

5.5

CVSS3.1

CVE-2025-38578 - f2fs: fix to avoid UAF in f2fs_sync_inode_meta()

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid UAF in f2fs_sync_inode_meta() syzbot reported an UAF issue as below: [1] [2] [1] https://syzkaller.appspot.com/text?tag=CrashReport&x=16594c60580000 ===========================================================…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:09 p.m.

7.8

CVSS3.1

CVE-2025-38574 - pptp: ensure minimal skb length in pptp_xmit()

In the Linux kernel, the following vulnerability has been resolved: pptp: ensure minimal skb length in pptp_xmit() Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data on ppp_sync_txmung") fixed ppp_sync_txmunge() We need a similar fix in pptp_xmit(), otherwise we might read uninit da…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 2:39 p.m.

7.8

CVSS3.1

CVE-2025-38570 - eth: fbnic: unlink NAPIs from queues on error to open

In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: unlink NAPIs from queues on error to open CI hit a UaF in fbnic in the AF_XDP portion of the queues.py test. The UaF is in the __sk_mark_napi_id_once() call in xsk_bind(), NAPI has been freed. Looks like the device fa…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 8:04 p.m.

7.8

CVSS3.1

CVE-2025-38568 - net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing

In the Linux kernel, the following vulnerability has been resolved: net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing TCA_MQPRIO_TC_ENTRY_INDEX is validated using NLA_POLICY_MAX(NLA_U32, TC_QOPT_MAX_QUEUE), which allows the value TC_QOPT_MAX_QUEUE (16). This leads to a 4-byte o…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 8:04 p.m.

7.8

CVSS3.1

CVE-2025-38565 - perf/core: Exit early on perf_mmap() fail

In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When perf_mmap() fails to allocate a buffer, it still invokes the event_mapped() callback of the related event. On X86 this might increase the perf_rdpmc_allowed reference counter. But no…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Jan. 8, 2026, 9:07 p.m.

5.5

CVSS3.1

CVE-2025-38562 - ksmbd: fix null pointer dereference error in generate_encryptionkey

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference error in generate_encryptionkey If client send two session setups with krb5 authenticate to ksmbd, null pointer dereference error in generate_encryptionkey could happen. sess->Preauth_HashValue…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: April 20, 2026, 4:30 p.m.

8.5

CVSS3.1

CVE-2025-38561 - ksmbd: fix Preauh_HashValue race condition

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Preauh_HashValue race condition If client send multiple session setup requests to ksmbd, Preauh_HashValue race condition could happen. There is no need to free sess->Preauh_HashValue at session setup phase. It can be f…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:48 p.m.

9.8

CVSS3.1

CVE-2024-44373 -

A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create a webshell and remote code execution via the path, content parameter to /includes/save_file.php.

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38590 - net/mlx5e: Remove skb secpath if xfrm state is not found

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Remove skb secpath if xfrm state is not found Hardware returns a unique identifier for a decrypted packet's xfrm state, this state is looked up in an xarray. However, the state might have been freed by the time of this…

πŸ“… Published: Aug. 19, 2025, midnight πŸ”„ Last Modified: Nov. 26, 2025, 5:58 p.m.
Total resulsts: 349182
Page 4232 of 34,919
Β« previous page Β» next page
Filters