5.5

CVSS3.1

CVE-2025-38388 - firmware: arm_ffa: Replace mutex with rwlock to avoid sleep in atomic context

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Replace mutex with rwlock to avoid sleep in atomic context The current use of a mutex to protect the notifier hashtable accesses can lead to issues in the atomic context. It results in the below kernel warnings…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 8:10 p.m.

6.1

CVSS3.1

CVE-2025-45406 -

A stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the debugbar_time parameter. NOTE: this is disputed by the Supplier because attackers cannot influence the value of debugbar_time, a…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2025-38462 - vsock: Fix transport_{g2h,h2g} TOCTOU

In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_{g2h,h2g} TOCTOU vsock_find_cid() and vsock_dev_do_ioctl() may race with module unload. transport_{g2h,h2g} may become NULL after the NULL check. Introduce vsock_transport_local_cid() to protect from a poten…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 9:52 p.m.

4.7

CVSS3.1

CVE-2025-38461 - vsock: Fix transport_* TOCTOU

In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment may race with module unload. Protect new_transport from becoming a stale pointer. This also takes care of an insecure call in vsock_use_local_transport(); add a lockdep assert. …

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 9:52 p.m.

5.5

CVSS3.1

CVE-2025-38452 - net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe()

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: rtsn: Fix a null pointer dereference in rtsn_probe() Add check for the return value of rcar_gen4_ptp_alloc() to prevent potential null pointer dereference.

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:52 p.m.

7.1

CVSS3.1

CVE-2025-38445 - md/raid1: Fix stack memory use after return in raid1_reshape

In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix stack memory use after return in raid1_reshape In the raid1_reshape function, newpool is allocated on the stack and assigned to conf->r1bio_pool. This results in conf->r1bio_pool.wait.head pointing to a stack addres…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 9:53 p.m.

5.5

CVSS3.1

CVE-2025-38444 - raid10: cleanup memleak at raid10_make_request

In the Linux kernel, the following vulnerability has been resolved: raid10: cleanup memleak at raid10_make_request If raid10_read_request or raid10_write_request registers a new request and the REQ_NOWAIT flag is set, the code does not free the malloc from the mempool. unreferenced object 0xffff…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 22, 2025, 9:53 p.m.

5.5

CVSS3.1

CVE-2025-38434 - Revert "riscv: Define TASK_SIZE_MAX for __access_ok()"

In the Linux kernel, the following vulnerability has been resolved: Revert "riscv: Define TASK_SIZE_MAX for __access_ok()" This reverts commit ad5643cf2f69 ("riscv: Define TASK_SIZE_MAX for __access_ok()"). This commit changes TASK_SIZE_MAX to be LONG_MAX to optimize access_ok(), because the pre…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 6:08 p.m.

5.5

CVSS3.1

CVE-2025-38432 - net: netpoll: Initialize UDP checksum field before checksumming

In the Linux kernel, the following vulnerability has been resolved: net: netpoll: Initialize UDP checksum field before checksumming commit f1fce08e63fe ("netpoll: Eliminate redundant assignment") removed the initialization of the UDP checksum, which was wrong and broke netpoll IPv6 transmission d…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 6:12 p.m.

7.8

CVSS3.1

CVE-2025-38422 - net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices

In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices Maximum OTP and EEPROM size for hearthstone PCI1xxxx devices are 8 Kb and 64 Kb respectively. Adjust max size definitions and return correct EEPROM length based on…

πŸ“… Published: July 25, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 6:41 p.m.
Total resulsts: 349182
Page 4524 of 34,919
Β« previous page Β» next page
Filters