5.5

CVSS3.1

CVE-2025-38282 - kernfs: Relax constraint in draining guard

In the Linux kernel, the following vulnerability has been resolved: kernfs: Relax constraint in draining guard The active reference lifecycle provides the break/unbreak mechanism but the active reference is not truly active after unbreak -- callers don't use it afterwards but it's important for p…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:50 p.m.

5.5

CVSS3.1

CVE-2025-38275 - phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug

In the Linux kernel, the following vulnerability has been resolved: phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug The qmp_usb_iomap() helper function currently returns the raw result of devm_ioremap() for non-exclusive mappings. Since devm_ioremap() may return a NULL pointer and the caller only …

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 4:52 p.m.

5.5

CVSS3.1

CVE-2025-38274 - fpga: fix potential null pointer deref in fpga_mgr_test_img_load_sgt()

In the Linux kernel, the following vulnerability has been resolved: fpga: fix potential null pointer deref in fpga_mgr_test_img_load_sgt() fpga_mgr_test_img_load_sgt() allocates memory for sgt using kunit_kzalloc() however it does not check if the allocation failed. It then passes sgt to sg_alloc…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 4:56 p.m.

5.5

CVSS3.1

CVE-2025-38271 - net: prevent a NULL deref in rtnl_create_link()

In the Linux kernel, the following vulnerability has been resolved: net: prevent a NULL deref in rtnl_create_link() At the time rtnl_create_link() is running, dev->netdev_ops is NULL, we must not use netdev_lock_ops() or risk a NULL deref if CONFIG_NET_SHAPER is defined. Use netif_set_group() in…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 4:53 p.m.

5.5

CVSS3.1

CVE-2025-38269 - btrfs: exit after state insertion failure at btrfs_convert_extent_bit()

In the Linux kernel, the following vulnerability has been resolved: btrfs: exit after state insertion failure at btrfs_convert_extent_bit() If insert_state() state failed it returns an error pointer and we call extent_io_tree_panic() which will trigger a BUG() call. However if CONFIG_BUG is disab…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:30 p.m.

7.1

CVSS3.1

CVE-2025-38340 - firmware: cs_dsp: Fix OOB memory read access in KUnit test

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Fix OOB memory read access in KUnit test KASAN reported out of bounds access - cs_dsp_mock_bin_add_name_or_info(), because the source string length was rounded up to the allocation size.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:52 p.m.

7.8

CVSS3.1

CVE-2025-38346 - ftrace: Fix UAF when lookup kallsym after ftrace disabled

In the Linux kernel, the following vulnerability has been resolved: ftrace: Fix UAF when lookup kallsym after ftrace disabled The following issue happens with a buggy module: BUG: unable to handle page fault for address: ffffffffc05d0218 PGD 1bd66f067 P4D 1bd66f067 PUD 1bd671067 PMD 101808067 PT…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 5:38 p.m.

6.1

CVSS3.1

CVE-2025-45662 -

A cross-site scripting (XSS) vulnerability in the component /master/login.php of mpgram-web commit 94baadb allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Oct. 17, 2025, 6:56 p.m.

5.5

CVSS3.1

CVE-2025-38333 - f2fs: fix to bail out in get_new_segment()

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to bail out in get_new_segment() ------------[ cut here ]------------ WARNING: CPU: 3 PID: 579 at fs/f2fs/segment.c:2832 new_curseg+0x5e8/0x6dc pc : new_curseg+0x5e8/0x6dc Call trace: new_curseg+0x5e8/0x6dc f2fs_alloc…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:53 p.m.

5.5

CVSS3.1

CVE-2025-38316 - wifi: mt76: mt7996: avoid NULL pointer dereference in mt7996_set_monitor()

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: avoid NULL pointer dereference in mt7996_set_monitor() The function mt7996_set_monitor() dereferences phy before the NULL sanity check. Fix this to avoid NULL pointer dereference by moving the dereference aft…

πŸ“… Published: July 10, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 12:54 p.m.
Total resulsts: 349182
Page 4699 of 34,919
Β« previous page Β» next page
Filters