7.8

CVSS3.1

CVE-2025-38250 - Bluetooth: hci_core: Fix use-after-free in vhci_flush()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix use-after-free in vhci_flush() syzbot reported use-after-free in vhci_flush() without repro. [0] From the splat, a thread close()d a vhci file descriptor while its device was being used by iotcl() on ano…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: March 25, 2026, 11:16 a.m.

6.5

CVSS3.1

CVE-2025-44526 -

Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet.

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: July 18, 2025, 5:48 p.m.

4.7

CVSS3.1

CVE-2025-38242 - mm: userfaultfd: fix race of userfaultfd_move and swap cache

In the Linux kernel, the following vulnerability has been resolved: mm: userfaultfd: fix race of userfaultfd_move and swap cache This commit fixes two kinds of races, they may have different results: Barry reported a BUG_ON in commit c50f8e6053b0, we may see the same BUG_ON if the filemap lookup…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 3:44 p.m.

6.5

CVSS3.1

CVE-2021-27961 -

evesys 7.1 (2152) through 8.0 (2202) allows Reflected XSS via the indexeva.php action parameter.

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2025-38260 - btrfs: handle csum tree error with rescue=ibadroots correctly

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle csum tree error with rescue=ibadroots correctly [BUG] There is syzbot based reproducer that can crash the kernel, with the following call trace: (With some debug output added) DEBUG: rescue=ibadroots parsed BTRFS…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 5:02 p.m.

5.5

CVSS3.1

CVE-2025-38262 - tty: serial: uartlite: register uart driver in init

In the Linux kernel, the following vulnerability has been resolved: tty: serial: uartlite: register uart driver in init When two instances of uart devices are probing, a concurrency race can occur. If one thread calls uart_register_driver function, which first allocates and assigns memory to 'uar…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:59 p.m.

7.8

CVSS3.1

CVE-2025-38257 - s390/pkey: Prevent overflow in size calculation for memdup_user()

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of siz…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 5:07 p.m.

7.8

CVSS3.1

CVE-2025-38259 - ASoC: codecs: wcd9335: Fix missing free of regulator supplies

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd9335: Fix missing free of regulator supplies Driver gets and enables all regulator supplies in probe path (wcd9335_parse_dt() and wcd9335_power_on_reset()), but does not cleanup in final error paths and in unbind…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 5:03 p.m.

7.8

CVSS3.1

CVE-2025-38245 - atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister().

In the Linux kernel, the following vulnerability has been resolved: atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister(). syzbot reported a warning below during atm_dev_register(). [0] Before creating a new device and procfs/sysfs for it, atm_dev_register() looks up a duplica…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 5:14 p.m.

5.5

CVSS3.1

CVE-2025-38252 - cxl/ras: Fix CPER handler device confusion

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix CPER handler device confusion By inspection, cxl_cper_handle_prot_err() is making a series of fragile assumptions that can lead to crashes: 1/ It assumes that endpoints identified in the record are a CXL-type-3 d…

πŸ“… Published: July 9, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 9:01 p.m.
Total resulsts: 347821
Page 4574 of 34,783
Β« previous page Β» next page
Filters