7.8

CVSS3.1

CVE-2025-38216 - iommu/vt-d: Restore context entry setup order for aliased devices

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Restore context entry setup order for aliased devices Commit 2031c469f816 ("iommu/vt-d: Add support for static identity domain") changed the context entry setup during domain attachment from a set-and-check policy to …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 3:45 p.m.

7.1

CVSS3.1

CVE-2025-38204 - jfs: fix array-index-out-of-bounds read in add_missing_indices

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds read in add_missing_indices stbl is s8 but it must contain offsets into slot which can go from 0 to 127. Added a bound check for that error and return -EIO if the check fails. Also make jfs_rea…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.

5.6

CVSS3.1

CVE-2025-48172 -

CHMLib through 2bef8d0, as used in SumatraPDF and other products, has a chm_lib.c _chm_decompress_block integer overflow. There is a resultant heap-based buffer overflow in _chm_fetch_bytes.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2025-38211 - RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction

In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction The commit 59c68ac31e15 ("iw_cm: free cm_id resources on the last deref") simplified cm_id resource management by freeing cm_id once all references to the cm_i…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:12 p.m.

4.7

CVSS3.1

CVE-2025-38232 - NFSD: fix race between nfsd registration and exports_proc

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and exports_proc As of now nfsd calls create_proc_exports_entry() at start of init_nfsd and cleanup by remove_proc_entry() at last of exit_nfsd. Which causes kernel OOPs if there is race …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 1:29 p.m.

7.8

CVSS3.1

CVE-2025-38227 - media: vidtv: Terminating the subsequent process of initialization failure

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: Terminating the subsequent process of initialization failure syzbot reported a slab-use-after-free Read in vidtv_mux_init. [1] After PSI initialization fails, the si member is accessed again, resulting in this uaf.…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:38 p.m.

5.5

CVSS3.1

CVE-2025-38199 - wifi: ath12k: Fix memory leak due to multiple rx_stats allocation

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix memory leak due to multiple rx_stats allocation rx_stats for each arsta is allocated when adding a station. arsta->rx_stats will be freed when a station is removed. Redundant allocations are occurring when the …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 5:17 p.m.

5.5

CVSS3.1

CVE-2025-38190 - atm: Revert atm_account_tx() if copy_from_iter_full() fails.

In the Linux kernel, the following vulnerability has been resolved: atm: Revert atm_account_tx() if copy_from_iter_full() fails. In vcc_sendmsg(), we account skb->truesize to sk->sk_wmem_alloc by atm_account_tx(). It is expected to be reverted by atm_pop_raw() later called by vcc->dev->ops->send…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 5:24 p.m.

7.8

CVSS3.1

CVE-2025-38175 - binder: fix yet another UAF in binder_devices

In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Commit e77aff5528a18 ("binderfs: fix use-after-free in binder_devices") addressed a use-after-free where devices could be released without first being removed from the binder_devices …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9:04 p.m.

9.3

CVSS3.1

CVE-2025-26850 -

The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346617
Page 4538 of 34,662
Β« previous page Β» next page
Filters