5.5

CVSS3.1

CVE-2022-49928 - SUNRPC: Fix null-ptr-deref when xps sysfs alloc failed

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix null-ptr-deref when xps sysfs alloc failed There is a null-ptr-deref when xps sysfs alloc failed: BUG: KASAN: null-ptr-deref in sysfs_do_create_link_sd+0x40/0xd0 Read of size 8 at addr 0000000000000030 by task gss…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2022-49885 - ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init()

In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init() Change num_ghes from int to unsigned int, preventing an overflow and causing subsequent vmalloc() to fail. The overflow happens in ghes_estatus_pool_init() when calcul…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 5:15 p.m.

6.3

CVSS3.1

CVE-2025-44854 -

TOTOLINK CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: May 22, 2025, 3:32 p.m.

5.5

CVSS3.1

CVE-2025-37787 - net: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered Russell King reports that a system with mv88e6xxx dereferences a NULL pointer when unbinding this driver: https://lore.kernel.org/netdev/Z_lRkMl…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

7.8

CVSS3.1

CVE-2025-37796 - wifi: at76c50x: fix use after free access in at76_disconnect

In the Linux kernel, the following vulnerability has been resolved: wifi: at76c50x: fix use after free access in at76_disconnect The memory pointed to by priv is freed at the end of at76_delete_device function (using ieee80211_free_hw). But the code then accesses the udev field of the freed objec…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-37792 - Bluetooth: btrtl: Prevent potential NULL dereference

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: Prevent potential NULL dereference The btrtl_initialize() function checks that rtl_load_file() either had an error or it loaded a zero length file. However, if it loaded a zero length file then the error code i…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:21 p.m.

7.8

CVSS3.1

CVE-2025-37789 - net: openvswitch: fix nested key length validation in the set() action

In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix nested key length validation in the set() action It's not safe to access nla_len(ovs_key) if the data is smaller than the netlink header. Check that the attribute is OK first.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 5:27 p.m.

7.8

CVSS3.1

CVE-2025-37777 - ksmbd: fix use-after-free in __smb2_lease_break_noti()

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __smb2_lease_break_noti() Move tcp_transport free to ksmbd_conn_free. If ksmbd connection is referenced when ksmbd server thread terminates, It will not be freed, but conn->tcp_transport is freed. __s…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 4:45 p.m.

5.5

CVSS3.1

CVE-2025-37770 - drm/amd/pm: Prevent division by zero

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Prevent division by zero The user can set any speed value. If speed is greater than UINT_MAX/8, division by zero is possible. Found by Linux Verification Center (linuxtesting.org) with SVACE.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 3:02 p.m.

5.5

CVSS3.1

CVE-2025-37766 - drm/amd/pm: Prevent division by zero

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Prevent division by zero The user can set any speed value. If speed is greater than UINT_MAX/8, division by zero is possible. Found by Linux Verification Center (linuxtesting.org) with SVACE.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 3:04 p.m.
Total resulsts: 349182
Page 5601 of 34,919
Β« previous page Β» next page
Filters