5.5

CVSS3.1

CVE-2025-21894 - net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC

In the Linux kernel, the following vulnerability has been resolved: net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC Actually ENETC VFs do not support HWTSTAMP_TX_ONESTEP_SYNC because only ENETC PF can access PMa_SINGLE_STEP registers. And there will be a crash if VFs are used to test one-…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:50 p.m.

5.5

CVSS3.1

CVE-2025-21961 - eth: bnxt: fix truesize for mb-xdp-pass case

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix truesize for mb-xdp-pass case When mb-xdp is set and return is XDP_PASS, packet is converted from xdp_buff to sk_buff with xdp_update_skb_shared_info() in bnxt_xdp_build_skb(). bnxt_xdp_build_skb() passes incorrect…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:15 p.m.

4.6

CVSS3.1

CVE-2025-28132 -

A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing a…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: June 18, 2025, 1:59 p.m.

5.5

CVSS3.1

CVE-2025-21922 - ppp: Fix KMSAN uninit-value warning with bpf

In the Linux kernel, the following vulnerability has been resolved: ppp: Fix KMSAN uninit-value warning with bpf Syzbot caught an "KMSAN: uninit-value" warning [1], which is caused by the ppp driver not initializing a 2-byte header when using socket filter. The following code can generate a PPP …

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.1

CVSS3.1

CVE-2025-21985 - drm/amd/display: Fix out-of-bound accesses

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bound accesses [WHAT & HOW] hpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4), but location can have size up to 6. As a result, it is necessary to check location against MAX_HPO_DP2_…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 7:17 p.m.

4.6

CVSS3.1

CVE-2025-28131 -

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling …

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: July 11, 2025, 1:39 p.m.

7.8

CVSS3.1

CVE-2025-21929 - HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove()

In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove() During the `rmmod` operation for the `intel_ishtp_hid` driver, a use-after-free issue can occur in the hid_ishtp_cl_remove() function. The function hid_ishtp_c…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:24 a.m.

7.8

CVSS3.1

CVE-2025-21896 - fuse: revert back to __readahead_folio() for readahead

In the Linux kernel, the following vulnerability has been resolved: fuse: revert back to __readahead_folio() for readahead In commit 3eab9d7bc2f4 ("fuse: convert readahead to use folios"), the logic was converted to using the new folio readahead code, which drops the reference on the folio once i…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:50 p.m.

5.4

CVSS3.1

CVE-2025-26056 -

A command injection vulnerability exists in the Infinxt iEdge 100 2.1.32 in the Troubleshoot module "MTR" functionality. The vulnerability is due to improper validation of user-supplied input in the mtrIp parameter. An attacker can exploit this flaw to execute arbitrary operating system commands on…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: April 14, 2025, 6:15 p.m.

5.5

CVSS3.1

CVE-2025-21909 - wifi: nl80211: reject cooked mode if it is set along with other flags

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject cooked mode if it is set along with other flags It is possible to set both MONITOR_FLAG_COOK_FRAMES and MONITOR_FLAG_ACTIVE flags simultaneously on the same monitor interface from the userspace. This causes …

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.
Total resulsts: 343436
Page 5520 of 34,344
Β« previous page Β» next page
Filters