5.5

CVSS3.1

CVE-2025-22103 - net: fix NULL pointer dereference in l3mdev_l3_rcv

In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer dereference in l3mdev_l3_rcv When delete l3s ipvlan: ip link del link eth0 ipvlan1 type ipvlan mode l3s This may cause a null pointer dereference: Call trace: ip_rcv_finish+0x48/0xd0 ip_…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 10:15 a.m.

5.5

CVSS3.1

CVE-2025-22037 - ksmbd: fix null pointer dereference in alloc_preauth_hash()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 session setup even thought conn->preauth_info is no…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Sept. 19, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-22072 - spufs: fix gang directory lifetimes

In the Linux kernel, the following vulnerability has been resolved: spufs: fix gang directory lifetimes prior to "[POWERPC] spufs: Fix gang destroy leaks" we used to have a problem with gang lifetimes - creation of a gang returns opened gang directory, which normally gets removed when that gets c…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2025-22033 - arm64: Don't call NULL in do_compat_alignment_fixup()

In the Linux kernel, the following vulnerability has been resolved: arm64: Don't call NULL in do_compat_alignment_fixup() do_alignment_t32_to_handler() only fixes up alignment faults for specific instructions; it returns NULL otherwise (e.g. LDREX). When that's the case, signal to the caller that…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2024-58092 - nfsd: fix legacy client tracking initialization

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix legacy client tracking initialization Get rid of the nfsd4_legacy_tracking_ops->init() call in check_for_legacy_methods(). That will be handled in the caller (nfsd4_client_tracking_init()). Otherwise, we'll wind up ca…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 7:11 p.m.

7.8

CVSS3.1

CVE-2025-22020 - memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove

In the Linux kernel, the following vulnerability has been resolved: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove This fixes the following crash: ================================================================== BUG: KASAN: slab-use-after-free in rtsx_usb_ms_poll_card…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2025-22120 - ext4: goto right label 'out_mmap_sem' in ext4_setattr()

In the Linux kernel, the following vulnerability has been resolved: ext4: goto right label 'out_mmap_sem' in ext4_setattr() Otherwise, if ext4_inode_attach_jinode() fails, a hung task will happen because filemap_invalidate_unlock() isn't called to unlock mapping->invalidate_lock. Like this: EXT4…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 6:28 p.m.

5.5

CVSS3.1

CVE-2025-22102 - Bluetooth: btnxpuart: Fix kernel panic during FW release

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Fix kernel panic during FW release This fixes a kernel panic seen during release FW in a stress test scenario where WLAN and BT FW download occurs simultaneously, and due to a HW bug, chip sends out only 1 b…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 5:04 p.m.

7.1

CVSS3.1

CVE-2023-53034 - ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans

In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and size. This would make xlate_pos negative. [ 23.734156] switchtec switchtec0: MW 0…

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

6.5

CVSS3.1

CVE-2024-53304 -

An issue in LRQA Nettitude PoshC2 after commit 09ee2cf allows unauthenticated attackers to connect to the C2 server and execute arbitrary commands via posing as an infected machine.

πŸ“… Published: April 16, 2025, midnight πŸ”„ Last Modified: April 17, 2025, 8:22 p.m.
Total resulsts: 343975
Page 5270 of 34,398
Β« previous page Β» next page
Filters