7.8

CVSS3.1

CVE-2025-38230 - jfs: validate AG parameters in dbMount() to prevent crashes

In the Linux kernel, the following vulnerability has been resolved: jfs: validate AG parameters in dbMount() to prevent crashes Validate db_agheight, db_agwidth, and db_agstart in dbMount to catch corrupted metadata early and avoid undefined behavior in dbAllocAG. Limits are derived from L2LPERCT…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:31 p.m.

5.5

CVSS3.1

CVE-2025-38185 - atm: atmtcp: Free invalid length skb in atmtcp_c_send().

In the Linux kernel, the following vulnerability has been resolved: atm: atmtcp: Free invalid length skb in atmtcp_c_send(). syzbot reported the splat below. [0] vcc_sendmsg() copies data passed from userspace to skb and passes it to vcc->dev->ops->send(). atmtcp_c_send() accesses skb->data as …

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:53 p.m.

5.5

CVSS3.1

CVE-2025-38225 - media: imx-jpeg: Cleanup after an allocation error

In the Linux kernel, the following vulnerability has been resolved: media: imx-jpeg: Cleanup after an allocation error When allocation failures are not cleaned up by the driver, further allocation errors will be false-positives, which will cause buffers to remain uninitialized and cause NULL poin…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 7:46 p.m.

5.5

CVSS3.1

CVE-2025-38194 - jffs2: check that raw node were preallocated before writing summary

In the Linux kernel, the following vulnerability has been resolved: jffs2: check that raw node were preallocated before writing summary Syzkaller detected a kernel bug in jffs2_link_node_ref, caused by fault injection in jffs2_prealloc_raw_node_refs. jffs2_sum_write_sumnode doesn't check return v…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:26 p.m.

4.9

CVSS3.1

CVE-2025-49600 -

In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation fails and internal errors go unchecked, enabling LMS (Leighton-Micali Signature) forgery in a fault scenario. Specifically, unchecked return values in mbedtls_lms_verify allow an attacker (who can in…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: July 17, 2025, 3:59 p.m.

7.1

CVSS3.1

CVE-2025-38221 - ext4: fix out of bounds punch offset

In the Linux kernel, the following vulnerability has been resolved: ext4: fix out of bounds punch offset Punching a hole with a start offset that exceeds max_end is not permitted and will result in a negative length in the truncate_inode_partial_folio() function while truncating the page cache, p…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 3:12 p.m.

5.5

CVSS3.1

CVE-2025-38215 - fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var

In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix do_register_framebuffer to prevent null-ptr-deref in fb_videomode_to_var If fb_add_videomode() in do_register_framebuffer() fails to allocate memory for fb_videomode, it will later lead to a null-ptr dereference in fb_…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 8:01 p.m.

7.8

CVSS3.1

CVE-2025-38182 - ublk: santizize the arguments from userspace when adding a device

In the Linux kernel, the following vulnerability has been resolved: ublk: santizize the arguments from userspace when adding a device Sanity check the values for queue depth and number of queues we get from userspace when adding a device.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9 p.m.

5.5

CVSS3.1

CVE-2025-38193 - net_sched: sch_sfq: reject invalid perturb period

In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: reject invalid perturb period Gerrard Tai reported that SFQ perturb_period has no range check yet, and this can be used to trigger a race condition fixed in a separate patch. We want to make sure ctl->perturb…

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 9:25 p.m.

5.3

CVSS3.1

CVE-2025-53602 -

Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.

πŸ“… Published: July 4, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346624
Page 4541 of 34,663
Β« previous page Β» next page
Filters