5.5

CVSS3.1

CVE-2023-4130 - ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea() There are multiple smb2_ea_info buffers in FILE_FULL_EA_INFORMATION request from client. ksmbd find next smb2_ea_info using ->NextEntryOffset of current smb2_e…

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:58 p.m.

5.5

CVSS3.1

CVE-2023-32246 - ksmbd: call rcu_barrier() in ksmbd_server_exit()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: call rcu_barrier() in ksmbd_server_exit() racy issue is triggered the bug by racing between closing a connection and rmmod. In ksmbd, rcu_barrier() is not called at module unload time, so nothing prevents ksmbd from gettin…

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 6:10 p.m.

5.5

CVSS3.1

CVE-2025-38547 - iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps

In the Linux kernel, the following vulnerability has been resolved: iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps The AXP717 ADC channel maps is missing a sentinel entry at the end. This causes a KASAN warning. Add the missing sentinel entry.

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 6:10 p.m.

5.5

CVSS3.1

CVE-2025-38546 - atm: clip: Fix memory leak of struct clip_vcc.

In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix memory leak of struct clip_vcc. ioctl(ATMARP_MKIP) allocates struct clip_vcc and set it to vcc->user_back. The code assumes that vcc_destroy_socket() passes NULL skb to vcc->push() when the socket is close()d, and…

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 6:33 p.m.

7.8

CVSS3.1

CVE-2025-38538 - dmaengine: nbpfaxi: Fix memory corruption in probe()

In the Linux kernel, the following vulnerability has been resolved: dmaengine: nbpfaxi: Fix memory corruption in probe() The nbpf->chan[] array is allocated earlier in the nbpf_probe() function and it has "num_channels" elements. These three loops iterate one element farther than they should and…

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 6:42 p.m.

7.8

CVSS3.1

CVE-2025-38535 - phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode

In the Linux kernel, the following vulnerability has been resolved: phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode When transitioning from USB_ROLE_DEVICE to USB_ROLE_NONE, the code assumed that the regulator should be disabled. However, if the regulator is marked as always-o…

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 6:56 p.m.

7.8

CVSS3.1

CVE-2025-38527 - smb: client: fix use-after-free in cifs_oplock_break

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-after-free in cifs_oplock_break A race condition can occur in cifs_oplock_break() leading to a use-after-free of the cinode structure when unmounting: cifs_oplock_break() _cifsFileInfo_put(cfile) …

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 5:38 p.m.

5.5

CVSS3.1

CVE-2025-38520 - drm/amdkfd: Don't call mmput from MMU notifier callback

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Don't call mmput from MMU notifier callback If the process is exiting, the mmput inside mmu notifier callback from compactd or fork or numa balancing could release the last reference of mm struct to call exit_mmap and…

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 5:39 p.m.

5.5

CVSS3.1

CVE-2025-38517 - lib/alloc_tag: do not acquire non-existent lock in alloc_tag_top_users()

In the Linux kernel, the following vulnerability has been resolved: lib/alloc_tag: do not acquire non-existent lock in alloc_tag_top_users() alloc_tag_top_users() attempts to lock alloc_tag_cttype->mod_lock even when the alloc_tag_cttype is not allocated because: 1) alloc tagging is disabled b…

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 9:51 p.m.

5.5

CVSS3.1

CVE-2025-38505 - wifi: mwifiex: discard erroneous disassoc frames on STA interface

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: discard erroneous disassoc frames on STA interface When operating in concurrent STA/AP mode with host MLME enabled, the firmware incorrectly sends disassociation frames to the STA interface when clients disconnect …

πŸ“… Published: Aug. 16, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:21 p.m.
Total resulsts: 349182
Page 4254 of 34,919
Β« previous page Β» next page
Filters