7.1

CVSS3.1

CVE-2023-53059 - platform/chrome: cros_ec_chardev: fix kernel data leak from ioctl

In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_chardev: fix kernel data leak from ioctl It is possible to peep kernel page's data by providing larger `insize` in struct cros_ec_command[1] when invoking EC host commands. Fix it by using zeroed memory.…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 3 p.m.

5.5

CVSS3.1

CVE-2023-53128 - scsi: mpi3mr: Fix throttle_groups memory leak

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Fix throttle_groups memory leak Add a missing kfree().

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:40 p.m.

5.5

CVSS3.1

CVE-2023-53113 - wifi: nl80211: fix NULL-ptr deref in offchan check

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: fix NULL-ptr deref in offchan check If, e.g. in AP mode, the link was already created by userspace but not activated yet, it has a chandef but the chandef isn't valid and has no channel. Check for this and ignore t…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:53 p.m.

5.5

CVSS3.1

CVE-2023-53098 - media: rc: gpio-ir-recv: add remove function

In the Linux kernel, the following vulnerability has been resolved: media: rc: gpio-ir-recv: add remove function In case runtime PM is enabled, do runtime PM clean up to remove cpu latency qos request, otherwise driver removal may have below kernel dump: [ 19.463299] Unable to handle kernel NU…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:18 a.m.

5.5

CVSS3.1

CVE-2023-53054 - usb: dwc2: fix a devres leak in hw_enable upon suspend resume

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: fix a devres leak in hw_enable upon suspend resume Each time the platform goes to low power, PM suspend / resume routines call: __dwc2_lowlevel_hw_enable -> devm_add_action_or_reset(). This adds a new devres each time.…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:53 p.m.

5.5

CVSS3.1

CVE-2022-49932 - KVM: VMX: Do _all_ initialization before exposing /dev/kvm to userspace

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Do _all_ initialization before exposing /dev/kvm to userspace Call kvm_init() only after _all_ setup is complete, as kvm_init() exposes /dev/kvm to userspace and thus allows userspace to create VMs (and call other ioctl…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:26 p.m.

5.5

CVSS3.1

CVE-2023-53067 - LoongArch: Only call get_timer_irq() once in constant_clockevent_init()

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Only call get_timer_irq() once in constant_clockevent_init() Under CONFIG_DEBUG_ATOMIC_SLEEP=y and CONFIG_DEBUG_PREEMPT=y, we can see the following messages on LoongArch, this is because using might_sleep() in preempti…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 8:52 p.m.

5.5

CVSS3.1

CVE-2023-53042 - drm/amd/display: Do not set DRR on pipe Commit

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not set DRR on pipe Commit [WHY] Writing to DRR registers such as OTG_V_TOTAL_MIN on the same frame as a pipe commit can cause underflow.

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 7:15 p.m.

5.5

CVSS3.1

CVE-2023-53041 - scsi: qla2xxx: Perform lockless command completion in abort path

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Perform lockless command completion in abort path While adding and removing the controller, the following call trace was observed: WARNING: CPU: 3 PID: 623596 at kernel/dma/mapping.c:532 dma_free_attrs+0x33/0x50 C…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:18 a.m.

5.5

CVSS3.1

CVE-2023-53108 - net/iucv: Fix size of interrupt data

In the Linux kernel, the following vulnerability has been resolved: net/iucv: Fix size of interrupt data iucv_irq_data needs to be 4 bytes larger. These bytes are not used by the iucv module, but written by the z/VM hypervisor in case a CPU is deconfigured. Reported as: BUG dma-kmalloc-64 (Not t…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:54 p.m.
Total resulsts: 343970
Page 5056 of 34,397
Β« previous page Β» next page
Filters