5.5

CVSS3.1

CVE-2023-53113 - wifi: nl80211: fix NULL-ptr deref in offchan check

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: fix NULL-ptr deref in offchan check If, e.g. in AP mode, the link was already created by userspace but not activated yet, it has a chandef but the chandef isn't valid and has no channel. Check for this and ignore t…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:53 p.m.

5.5

CVSS3.1

CVE-2023-53098 - media: rc: gpio-ir-recv: add remove function

In the Linux kernel, the following vulnerability has been resolved: media: rc: gpio-ir-recv: add remove function In case runtime PM is enabled, do runtime PM clean up to remove cpu latency qos request, otherwise driver removal may have below kernel dump: [ 19.463299] Unable to handle kernel NU…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:18 a.m.

5.5

CVSS3.1

CVE-2023-53054 - usb: dwc2: fix a devres leak in hw_enable upon suspend resume

In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: fix a devres leak in hw_enable upon suspend resume Each time the platform goes to low power, PM suspend / resume routines call: __dwc2_lowlevel_hw_enable -> devm_add_action_or_reset(). This adds a new devres each time.…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 5:53 p.m.

5.5

CVSS3.1

CVE-2022-49932 - KVM: VMX: Do _all_ initialization before exposing /dev/kvm to userspace

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Do _all_ initialization before exposing /dev/kvm to userspace Call kvm_init() only after _all_ setup is complete, as kvm_init() exposes /dev/kvm to userspace and thus allows userspace to create VMs (and call other ioctl…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:26 p.m.

5.5

CVSS3.1

CVE-2023-53067 - LoongArch: Only call get_timer_irq() once in constant_clockevent_init()

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Only call get_timer_irq() once in constant_clockevent_init() Under CONFIG_DEBUG_ATOMIC_SLEEP=y and CONFIG_DEBUG_PREEMPT=y, we can see the following messages on LoongArch, this is because using might_sleep() in preempti…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 8:52 p.m.

7.8

CVSS3.1

CVE-2023-53053 - erspan: do not use skb_mac_header() in ndo_start_xmit()

In the Linux kernel, the following vulnerability has been resolved: erspan: do not use skb_mac_header() in ndo_start_xmit() Drivers should not assume skb_mac_header(skb) == skb->data in their ndo_start_xmit(). Use skb_network_offset() and skb_transport_offset() which better describe what is need…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 6 p.m.

5.5

CVSS3.1

CVE-2023-53042 - drm/amd/display: Do not set DRR on pipe Commit

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not set DRR on pipe Commit [WHY] Writing to DRR registers such as OTG_V_TOTAL_MIN on the same frame as a pipe commit can cause underflow.

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 7:15 p.m.

9.8

CVSS3.1

CVE-2025-44872 -

Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: May 27, 2025, 2:21 p.m.

5.5

CVSS3.1

CVE-2023-53108 - net/iucv: Fix size of interrupt data

In the Linux kernel, the following vulnerability has been resolved: net/iucv: Fix size of interrupt data iucv_irq_data needs to be 4 bytes larger. These bytes are not used by the iucv module, but written by the z/VM hypervisor in case a CPU is deconfigured. Reported as: BUG dma-kmalloc-64 (Not t…

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 5:54 p.m.

9.8

CVSS3.1

CVE-2025-45800 -

TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the /lib/cste_modules/global.so library, specifically in the processing of the deviceMac parameter.

πŸ“… Published: May 2, 2025, midnight πŸ”„ Last Modified: June 4, 2025, 5:26 p.m.
Total resulsts: 349182
Page 5577 of 34,919
Β« previous page Β» next page
Filters