5.5

CVSS3.1

CVE-2025-21939 - drm/xe/hmm: Don't dereference struct page pointers without notifier lock

In the Linux kernel, the following vulnerability has been resolved: drm/xe/hmm: Don't dereference struct page pointers without notifier lock The pnfs that we obtain from hmm_range_fault() point to pages that we don't have a reference on, and the guarantee that they are still in the cpu page-table…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 7:44 p.m.

5.5

CVSS3.1

CVE-2025-21916 - usb: atm: cxacru: fix a flaw in existing endpoint checks

In the Linux kernel, the following vulnerability has been resolved: usb: atm: cxacru: fix a flaw in existing endpoint checks Syzbot once again identified a flaw in usb endpoint checking, see [1]. This time the issue stems from a commit authored by me (2eabb655a968 ("usb: atm: cxacru: fix endpoint…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.3

CVSS3.1

CVE-2025-29069 -

A heap buffer overflow vulnerability has been identified in the lcms2-2.16. The vulnerability exists in the UnrollChunkyBytes function in cmspack.c, which is responsible for handling color space transformations. NOTE: this is disputed by the Supplier because the finding identified a bug in a third-…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: April 4, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2025-21942 - btrfs: zoned: fix extent range end unlock in cow_file_range()

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix extent range end unlock in cow_file_range() Running generic/751 on the for-next branch often results in a hang like below. They are both stack by locking an extent. This suggests someone forget to unlock an exte…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 7:43 p.m.

5.5

CVSS3.1

CVE-2025-21911 - drm/imagination: avoid deadlock on fence release

In the Linux kernel, the following vulnerability has been resolved: drm/imagination: avoid deadlock on fence release Do scheduler queue fence release processing on a workqueue, rather than in the release function itself. Fixes deadlock issues such as the following: [ 607.400437] ==============…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

7.3

CVSS3.1

CVE-2025-27829 -

An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces. That could result in a denial of the multicast routing service on the firewall.

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: April 14, 2025, 6:15 p.m.

5.5

CVSS3.1

CVE-2025-21959 - netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() Since commit b36e4523d4d5 ("netfilter: nf_conncount: fix garbage collection confirm race"), `cpu` and `jiffies32` were introduced to the struct …

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

6.7

CVSS3.1

CVE-2023-46988 -

Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 10:53 a.m.

7.8

CVSS3.1

CVE-2025-21927 - nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu() nvme_tcp_recv_pdu() doesn't check the validity of the header length. When header digests are enabled, a target might send a packet with an invalid header length (e.…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21898 - ftrace: Avoid potential division by zero in function_stat_show()

In the Linux kernel, the following vulnerability has been resolved: ftrace: Avoid potential division by zero in function_stat_show() Check whether denominator expression x * (x - 1) * 1000 mod {2^32, 2^64} produce zero and skip stddev computation in that case. For now don't care about rec->count…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.
Total resulsts: 343738
Page 5554 of 34,374
Β« previous page Β» next page
Filters