5.5

CVSS3.1

CVE-2025-38402 - idpf: return 0 size for RSS key if not supported

In the Linux kernel, the following vulnerability has been resolved: idpf: return 0 size for RSS key if not supported Returning -EOPNOTSUPP from function returning u32 is leading to cast and invalid size value as a result. -EOPNOTSUPP as a size probably will lead to allocation fail. Command: eth…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 6:18 p.m.

7.8

CVSS3.1

CVE-2025-38385 - net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect

In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect Remove redundant netif_napi_del() call from disconnect path. A WARN may be triggered in __netif_napi_del_locked() during USB device disconnect: WARNING: CPU…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:12 p.m.

7.1

CVSS3.1

CVE-2025-45467 -

Unitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements an insecure verification mechanism that solely relies on MD5 checksums for firmware integrity validation.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Jan. 12, 2026, 4:28 p.m.

5.5

CVSS3.1

CVE-2025-38429 - bus: mhi: ep: Update read pointer only after buffer is written

In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Update read pointer only after buffer is written Inside mhi_ep_ring_add_element, the read pointer (rd_offset) is updated before the buffer is written, potentially causing race conditions where the host sees an updat…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 6:59 p.m.

7.8

CVSS3.1

CVE-2025-38421 - platform/x86/amd: pmf: Use device managed allocations

In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd: pmf: Use device managed allocations If setting up smart PC fails for any reason then this can lead to a double free when unloading amd-pmf. This is because dev->buf was freed but never set to NULL and is again …

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 6:59 p.m.

7.8

CVSS3.1

CVE-2025-38403 - vsock/vmci: Clear the vmci transport packet properly when initializing it

In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: Clear the vmci transport packet properly when initializing it In vmci_transport_packet_init memset the vmci_transport_packet before populating the fields to avoid any uninitialised data being left in the structure.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 7:42 p.m.

7.8

CVSS3.1

CVE-2025-38401 - mtk-sd: Prevent memory corruption from DMA map failure

In the Linux kernel, the following vulnerability has been resolved: mtk-sd: Prevent memory corruption from DMA map failure If msdc_prepare_data() fails to map the DMA region, the request is not prepared for data receiving, but msdc_start_data() proceeds the DMA with previous setting. Since this w…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 7:37 p.m.

5.5

CVSS3.1

CVE-2025-38455 - KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation is in-flight

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation is in-flight Reject migration of SEV{-ES} state if either the source or destination VM is actively creating a vCPU, i.e. if kvm_vm_ioctl_create_vcpu() is in the sect…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 9:54 p.m.

5.5

CVSS3.1

CVE-2025-38382 - btrfs: fix iteration of extrefs during log replay

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix iteration of extrefs during log replay At __inode_add_ref() when processing extrefs, if we jump into the next label we have an undefined value of victim_name.len, since we haven't initialized it before we did the goto.…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:11 p.m.

7.8

CVSS3.1

CVE-2025-38366 - LoongArch: KVM: Check validity of "num_cpu" from user space

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Check validity of "num_cpu" from user space The maximum supported cpu number is EIOINTC_ROUTE_MAX_VCPUS about irqchip EIOINTC, here add validation about cpu number to avoid array pointer overflow.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 8:29 p.m.
Total resulsts: 346571
Page 4253 of 34,658
Β« previous page Β» next page
Filters