5.5

CVSS3.1

CVE-2022-49824 - ata: libata-transport: fix error handling in ata_tlink_add()

In the Linux kernel, the following vulnerability has been resolved: ata: libata-transport: fix error handling in ata_tlink_add() In ata_tlink_add(), the return value of transport_add_device() is not checked. As a result, it causes null-ptr-deref while removing the module, because transport_remove…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 10, 2025, 8:16 p.m.

7.8

CVSS3.1

CVE-2022-49770 - ceph: avoid putting the realm twice when decoding snaps fails

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it'll put it twice and could cause random …

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 9:45 p.m.

6.5

CVSS3.1

CVE-2025-44863 -

TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: May 21, 2025, 7:47 p.m.

7.1

CVSS3.1

CVE-2022-49865 - ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network

In the Linux kernel, the following vulnerability has been resolved: ipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network When copying a `struct ifaddrlblmsg` to the network, __ifal_reserved remained uninitialized, resulting in a 1-byte infoleak: BUG: KMSAN: kernel-network-…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Jan. 23, 2026, 4:48 p.m.

5.5

CVSS3.1

CVE-2025-23140 - misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error

In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error After devm_request_irq() fails with error in pci_endpoint_test_request_irq(), the pci_endpoint_test_free_irq_vectors() is called assuming that a…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 9:46 p.m.

6.5

CVSS3.1

CVE-2025-46632 -

Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: May 27, 2025, 2:17 p.m.

5.5

CVSS3.1

CVE-2025-37743 - wifi: ath12k: Avoid memory leak while enabling statistics

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid memory leak while enabling statistics Driver uses monitor destination rings for extended statistics mode and standalone monitor mode. In extended statistics mode, TLVs are parsed from the buffer received from …

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 4:05 p.m.

5.5

CVSS3.1

CVE-2025-37746 - perf/dwc_pcie: fix duplicate pci_dev devices

In the Linux kernel, the following vulnerability has been resolved: perf/dwc_pcie: fix duplicate pci_dev devices During platform_device_register, wrongly using struct device pci_dev as platform_data caused a kmemdup copy of pci_dev. Worse still, accessing the duplicated device leads to list corru…

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 5, 2025, 4:07 p.m.

6.3

CVSS3.1

CVE-2025-44866 -

Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: May 27, 2025, 4:44 p.m.

5.5

CVSS3.1

CVE-2025-37774 - slab: ensure slab->obj_exts is clear in a newly allocated slab page

In the Linux kernel, the following vulnerability has been resolved: slab: ensure slab->obj_exts is clear in a newly allocated slab page ktest recently reported crashes while running several buffered io tests with __alloc_tagging_slab_alloc_hook() at the top of the crash call stack. The signature …

πŸ“… Published: May 1, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 9:43 p.m.
Total resulsts: 349182
Page 5605 of 34,919
Β« previous page Β» next page
Filters