5.5

CVSS3.1

CVE-2025-38470 - net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime

In the Linux kernel, the following vulnerability has been resolved: net: vlan: fix VLAN 0 refcount imbalance of toggling filtering during runtime Assuming the "rx-vlan-filter" feature is enabled on a net device, the 8021q module will automatically add or remove VLAN 0 when the net device is put a…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:34 p.m.

7.8

CVSS3.1

CVE-2025-38471 - tls: always refresh the queue when reading sock

In the Linux kernel, the following vulnerability has been resolved: tls: always refresh the queue when reading sock After recent changes in net-next TCP compacts skbs much more aggressively. This unearthed a bug in TLS where we may try to operate on an old skb when checking if all skbs in the que…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:34 p.m.

5.5

CVSS3.1

CVE-2025-38472 - netfilter: nf_conntrack: fix crash due to removal of uninitialised entry

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry A crash in conntrack was reported while trying to unlink the conntrack entry from the hash bucket list: [exception RIP: __nf_ct_delete_from_lists+172] …

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:34 p.m.

5.5

CVSS3.1

CVE-2025-38473 - Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() syzbot reported null-ptr-deref in l2cap_sock_resume_cb(). [0] l2cap_sock_resume_cb() has a similar problem that was fixed by commit 1bff51ea59a9 ("Bluetooth: fix use-after-…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:29 p.m.

7.8

CVSS3.1

CVE-2025-38476 - rpl: Fix use-after-free in rpl_do_srh_inline().

In the Linux kernel, the following vulnerability has been resolved: rpl: Fix use-after-free in rpl_do_srh_inline(). Running lwt_dst_cache_ref_loop.sh in selftest with KASAN triggers the splat below [0]. rpl_do_srh_inline() fetches ipv6_hdr(skb) and accesses it after skb_cow_head(), which is ille…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 7:28 p.m.

4.7

CVSS3.1

CVE-2025-38477 - net/sched: sch_qfq: Fix race condition on qfq_aggregate

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can occur when 'agg' is modified in qfq_change_agg (called during qfq_enqueue) while other threads access it concurrently. For example, qfq_dump_class may t…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:28 p.m.

5.5

CVSS3.1

CVE-2025-38478 - comedi: Fix initialization of data for instructions that write to subdevice

In the Linux kernel, the following vulnerability has been resolved: comedi: Fix initialization of data for instructions that write to subdevice Some Comedi subdevice instruction handlers are known to access instruction data elements beyond the first `insn->n` elements in some cases. The `do_insn…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:27 p.m.

7.8

CVSS3.1

CVE-2025-38485 - iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush

In the Linux kernel, the following vulnerability has been resolved: iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush fxls8962af_fifo_flush() uses indio_dev->active_scan_mask (with iio_for_each_active_channel()) without making sure the indio_dev stays in buffer mode. There is a …

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 4:25 p.m.

5.5

CVSS3.1

CVE-2025-38489 - s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again

In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again Commit 7ded842b356d ("s390/bpf: Fix bpf_plt pointer arithmetic") has accidentally removed the critical piece of commit c730fce7c70c ("s390/bpf: Fix bpf_arch_text_poke…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:45 p.m.

7.8

CVSS3.1

CVE-2025-38494 - HID: core: do not bypass hid_hw_raw_request

In the Linux kernel, the following vulnerability has been resolved: HID: core: do not bypass hid_hw_raw_request hid_hw_raw_request() is actually useful to ensure the provided buffer and length are valid. Directly calling in the low level transport driver function bypassed those checks and allowed…

πŸ“… Published: July 28, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4 p.m.
Total resulsts: 349182
Page 4495 of 34,919
Β« previous page Β» next page
Filters