7.8

CVSS3.1

CVE-2025-37786 - net: dsa: free routing table on probe failure

In the Linux kernel, the following vulnerability has been resolved: net: dsa: free routing table on probe failure If complete = true in dsa_tree_setup(), it means that we are the last switch of the tree which is successfully probing, and we should be setting up all switches from our probe path. …

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 2:55 p.m.

5.5

CVSS3.1

CVE-2025-23144 - backlight: led_bl: Hold led_access lock when calling led_sysfs_disable()

In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() Lockdep detects the following issue on led-backlight removal: [ 142.315935] ------------[ cut here ]------------ [ 142.315954] WARNING: CPU: 2 PID: 29…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 5:39 p.m.

7.8

CVSS3.1

CVE-2025-37750 - smb: client: fix UAF in decryption with multichannel

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in decryption with multichannel After commit f7025d861694 ("smb: client: allocate crypto only for primary server") and commit b0abcd65ec54 ("smb: client: fix UAF in async decryption"), the channels started re…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 9:31 p.m.

5.5

CVSS3.1

CVE-2022-49931 - IB/hfi1: Correctly move list in sc_disable()

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Correctly move list in sc_disable() Commit 13bac861952a ("IB/hfi1: Fix abba locking issue with sc_disable()") incorrectly tries to move a list from one list head to another. The result is a kernel crash. The crash is t…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2022-49898 - btrfs: fix tree mod log mishandling of reallocated nodes

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix tree mod log mishandling of reallocated nodes We have been seeing the following panic in production kernel BUG at fs/btrfs/tree-mod-log.c:677! invalid opcode: 0000 [#1] SMP RIP: 0010:tree_mod_log_rewind+0x1b4/0x…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 9:18 p.m.

5.5

CVSS3.1

CVE-2022-49916 - rose: Fix NULL pointer dereference in rose_send_frame()

In the Linux kernel, the following vulnerability has been resolved: rose: Fix NULL pointer dereference in rose_send_frame() The syzkaller reported an issue: KASAN: null-ptr-deref in range [0x0000000000000380-0x0000000000000387] CPU: 0 PID: 4069 Comm: kworker/0:15 Not tainted 6.0.0-syzkaller-0273…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 4:15 p.m.

5.5

CVSS3.1

CVE-2022-49904 - net, neigh: Fix null-ptr-deref in neigh_table_clear()

In the Linux kernel, the following vulnerability has been resolved: net, neigh: Fix null-ptr-deref in neigh_table_clear() When IPv6 module gets initialized but hits an error in the middle, kenel panic with: KASAN: null-ptr-deref in range [0x0000000000000598-0x000000000000059f] CPU: 1 PID: 361 Co…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 4:15 p.m.

7.3

CVSS3.1

CVE-2025-46626 -

Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: May 27, 2025, 2:22 p.m.

6.5

CVSS3.1

CVE-2025-44844 -

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: May 22, 2025, 3:31 p.m.

6.5

CVSS3.1

CVE-2025-44842 -

TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: May 22, 2025, 3:30 p.m.
Total resulsts: 343168
Page 5016 of 34,317
Β« previous page Β» next page
Filters