7.8

CVSS3.1

CVE-2025-38341 - eth: fbnic: avoid double free when failing to DMA-map FW msg

In the Linux kernel, the following vulnerability has been resolved: eth: fbnic: avoid double free when failing to DMA-map FW msg The semantics are that caller of fbnic_mbx_map_msg() retains the ownership of the message on error. All existing callers dutifully free the page.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:52 p.m.

7.1

CVSS3.1

CVE-2025-38329 - firmware: cs_dsp: Fix OOB memory read access in KUnit test (wmfw info)

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUnit test (wmfw info) KASAN reported out of bounds access - cs_dsp_mock_wmfw_add_info(), because the source string length was rounded up to the allocation size.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:53 p.m.

5.5

CVSS3.1

CVE-2025-38324 - mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu().

In the Linux kernel, the following vulnerability has been resolved: mpls: Use rcu_dereference_rtnl() in mpls_route_input_rcu(). As syzbot reported [0], mpls_route_input_rcu() can be called from mpls_getroute(), where is under RTNL. net->mpls.platform_label is only updated under RTNL. Let's use …

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 4:55 p.m.

5.5

CVSS3.1

CVE-2025-38290 - wifi: ath12k: fix node corruption in ar->arvifs list

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix node corruption in ar->arvifs list In current WLAN recovery code flow, ath12k_core_halt() only reinitializes the "arvifs" list head. This will cause the list node immediately following the list head to become an…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 8:39 p.m.

3.5

CVSS3.1

CVE-2023-50458 -

In Dradis before 4.11.0, the Output Console shows a job queue that may contain information about other users' jobs.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 7, 2025, 1:03 a.m.

5.5

CVSS3.1

CVE-2025-38336 - ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330

In the Linux kernel, the following vulnerability has been resolved: ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330 The controller has a hardware bug that can hard hang the system when doing ATAPI DMAs without any trace of what happened. Depending on the device attached, it can also p…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.

7.8

CVSS3.1

CVE-2025-38288 - scsi: smartpqi: Fix smp_processor_id() call trace for preemptible kernels

In the Linux kernel, the following vulnerability has been resolved: scsi: smartpqi: Fix smp_processor_id() call trace for preemptible kernels Correct kernel call trace when calling smp_processor_id() when called in preemptible kernels by using raw_smp_processor_id(). smp_processor_id() checks to…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 1:36 p.m.

5.5

CVSS3.1

CVE-2025-38281 - wifi: mt76: mt7996: Add NULL check in mt7996_thermal_init

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Add NULL check in mt7996_thermal_init devm_kasprintf() can return a NULL pointer on failure,but this returned value in mt7996_thermal_init() is not checked. Add NULL check in mt7996_thermal_init(), to handle k…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9:59 p.m.

10

CVSS3.1

CVE-2025-47812 -

In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thu…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

5.5

CVSS3.1

CVE-2025-38310 - seg6: Fix validation of nexthop addresses

In the Linux kernel, the following vulnerability has been resolved: seg6: Fix validation of nexthop addresses The kernel currently validates that the length of the provided nexthop address does not exceed the specified length. This can lead to the kernel reading uninitialized memory if user space…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 19, 2025, 5:58 p.m.
Total resulsts: 345143
Page 4294 of 34,515
Β« previous page Β» next page
Filters