5.5

CVSS3.1

CVE-2025-23159 - media: venus: hfi: add a check to handle OOB in sfr region

In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than actual sfr data buffer. Cap the size to a…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:53 p.m.

7.1

CVSS3.1

CVE-2025-23156 - media: venus: hfi_parser: refactor hfi packet parsing logic

In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi_parser: refactor hfi packet parsing logic words_count denotes the number of words in total payload, while data points to payload of various property within it. When words_count reaches last word, data can access…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 5:57 p.m.

5.5

CVSS3.1

CVE-2025-23154 - io_uring/net: fix io_req_post_cqe abuse by send bundle

In the Linux kernel, the following vulnerability has been resolved: io_uring/net: fix io_req_post_cqe abuse by send bundle [ 114.987980][ T5313] WARNING: CPU: 6 PID: 5313 at io_uring/io_uring.c:872 io_req_post_cqe+0x12e/0x4f0 [ 114.991597][ T5313] RIP: 0010:io_req_post_cqe+0x12e/0x4f0 [ 115.00…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 3:26 p.m.

5.5

CVSS3.1

CVE-2022-49930 - RDMA/hns: Fix NULL pointer problem in free_mr_init()

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix NULL pointer problem in free_mr_init() Lock grab occurs in a concurrent scenario, resulting in stepping on a NULL pointer. It should be init mutex_init() first before use the lock. Unable to handle kernel NULL p…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2022-49929 - RDMA/rxe: Fix mr leak in RESPST_ERR_RNR

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix mr leak in RESPST_ERR_RNR rxe_recheck_mr() will increase mr's ref_cnt, so we should call rxe_put(mr) to drop mr's ref_cnt in RESPST_ERR_RNR to avoid below warning: WARNING: CPU: 0 PID: 4156 at drivers/infiniband/…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 3:57 p.m.

5.5

CVSS3.1

CVE-2022-49923 - nfc: nxp-nci: Fix potential memory leak in nxp_nci_send()

In the Linux kernel, the following vulnerability has been resolved: nfc: nxp-nci: Fix potential memory leak in nxp_nci_send() nxp_nci_send() will call nxp_nci_i2c_write(), and only free skb when nxp_nci_i2c_write() failed. However, even if the nxp_nci_i2c_write() run succeeds, the skb will not be…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2022-49922 - nfc: nfcmrvl: Fix potential memory leak in nfcmrvl_i2c_nci_send()

In the Linux kernel, the following vulnerability has been resolved: nfc: nfcmrvl: Fix potential memory leak in nfcmrvl_i2c_nci_send() nfcmrvl_i2c_nci_send() will be called by nfcmrvl_nci_send(), and skb should be freed in nfcmrvl_i2c_nci_send(). However, nfcmrvl_nci_send() will only free skb when…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:15 p.m.

7.8

CVSS3.1

CVE-2022-49921 - net: sched: Fix use after free in red_enqueue()

In the Linux kernel, the following vulnerability has been resolved: net: sched: Fix use after free in red_enqueue() We can't use "skb" again after passing it to qdisc_enqueue(). This is basically identical to commit 2f09707d0c97 ("sch_sfb: Also store skb len before calling child enqueue").

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:15 p.m.

7.8

CVSS3.1

CVE-2022-49917 - ipvs: fix WARNING in ip_vs_app_net_cleanup()

In the Linux kernel, the following vulnerability has been resolved: ipvs: fix WARNING in ip_vs_app_net_cleanup() During the initialization of ip_vs_app_net_init(), if file ip_vs_app fails to be created, the initialization is successful by default. Therefore, the ip_vs_app file doesn't be found du…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 12, 2025, 4:06 p.m.

5.5

CVSS3.1

CVE-2022-49915 - mISDN: fix possible memory leak in mISDN_register_device()

In the Linux kernel, the following vulnerability has been resolved: mISDN: fix possible memory leak in mISDN_register_device() Afer commit 1fa5ae857bb1 ("driver core: get rid of struct device's bus_id string array"), the name of device is allocated dynamically, add put_device() to give up the ref…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 4:15 p.m.
Total resulsts: 349182
Page 5593 of 34,919
Β« previous page Β» next page
Filters