5.5

CVSS3.1

CVE-2025-37912 - ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr()

In the Linux kernel, the following vulnerability has been resolved: ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr() As mentioned in the commit baeb705fd6a7 ("ice: always check VF VSI pointer values"), we need to perform a null pointer check on the return value of ice_get_vf_vsi() before…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 6:11 p.m.

5.5

CVSS3.1

CVE-2025-37897 - wifi: plfxlc: Remove erroneous assert in plfxlc_mac_release

In the Linux kernel, the following vulnerability has been resolved: wifi: plfxlc: Remove erroneous assert in plfxlc_mac_release plfxlc_mac_release() asserts that mac->lock is held. This assertion is incorrect, because even if it was possible, it would not be the valid behaviour. The function is u…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 2:37 p.m.

7.8

CVSS3.1

CVE-2025-37892 - mtd: inftlcore: Add error check for inftl_read_oob()

In the Linux kernel, the following vulnerability has been resolved: mtd: inftlcore: Add error check for inftl_read_oob() In INFTL_findwriteunit(), the return value of inftl_read_oob() need to be checked. A proper implementation can be found in INFTL_deleteblock(). The status will be set as SECTOR…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 8:35 p.m.

5.5

CVSS3.1

CVE-2025-37989 - net: phy: leds: fix memory leak

In the Linux kernel, the following vulnerability has been resolved: net: phy: leds: fix memory leak A network restart test on a router led to an out-of-memory condition, which was traced to a memory leak in the PHY LED trigger code. The root cause is misuse of the devm API. The registration func…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:19 p.m.

5.5

CVSS3.1

CVE-2025-37950 - ocfs2: fix panic in failed foilio allocation

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix panic in failed foilio allocation commit 7e119cff9d0a ("ocfs2: convert w_pages to w_folios") and commit 9a5e08652dc4b ("ocfs2: use an array of folios instead of an array of pages") save -ENOMEM in the folio array upon …

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:57 p.m.

7.8

CVSS3.1

CVE-2025-37908 - mm, slab: clean up slab->obj_exts always

In the Linux kernel, the following vulnerability has been resolved: mm, slab: clean up slab->obj_exts always When memory allocation profiling is disabled at runtime or due to an error, shutdown_mem_profiling() is called: slab->obj_exts which previously allocated remains. It won't be cleared by un…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 2:58 p.m.

5.5

CVSS3.1

CVE-2025-37949 - xenbus: Use kref to track req lifetime

In the Linux kernel, the following vulnerability has been resolved: xenbus: Use kref to track req lifetime Marek reported seeing a NULL pointer fault in the xenbus_thread callstack: BUG: kernel NULL pointer dereference, address: 0000000000000000 RIP: e030:__wake_up_common+0x4c/0x180 Call Trace: …

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:05 p.m.

9.8

CVSS3.1

CVE-2025-44885 -

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 3:54 p.m.

5.5

CVSS3.1

CVE-2025-37918 - Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue() A NULL pointer dereference can occur in skb_dequeue() when processing a QCA firmware crash dump on WCN7851 (0489:e0f3). [ 93.672166] Bluetooth: hci0: ACL memdump …

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 4:52 p.m.

9.8

CVSS3.1

CVE-2025-44881 -

A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: May 30, 2025, 1:20 a.m.
Total resulsts: 349182
Page 5316 of 34,919
Β« previous page Β» next page
Filters