5.5

CVSS3.1

CVE-2025-21857 - net/sched: cls_api: fix error handling causing NULL dereference

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix error handling causing NULL dereference tcf_exts_miss_cookie_base_alloc() calls xa_alloc_cyclic() which can return 1 if the allocation succeeded after wrapping. This was treated as an error, with value 1 r…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.6

CVSS3.1

CVE-2025-25566 -

Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function. NOTE: the Supplier disputes this because the behavior is limited to a single allocation of a few hundred bytes with a command-line tool.

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: July 19, 2025, 2:15 a.m.

7.8

CVSS3.1

CVE-2025-21856 - s390/ism: add release function for struct device

In the Linux kernel, the following vulnerability has been resolved: s390/ism: add release function for struct device According to device_release() in /drivers/base/core.c, a device without a release function is a broken device and must be fixed. The current code directly frees the device after c…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21849 - drm/i915/gt: Use spin_lock_irqsave() in interruptible context

In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Use spin_lock_irqsave() in interruptible context spin_lock/unlock() functions used in interrupt contexts could result in a deadlock, as seen in GitLab issue #13399, which occurs when interrupt comes in while holding …

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21846 - acct: perform last write from workqueue

In the Linux kernel, the following vulnerability has been resolved: acct: perform last write from workqueue In [1] it was reported that the acct(2) system call can be used to trigger NULL deref in cases where it is set to write to a file that triggers an internal lookup. This can e.g., happen whe…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

9.8

CVSS3.1

CVE-2025-25568 -

SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN software, but is instead in a separate tool that has no untrusted input and runs under the user's own…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: July 19, 2025, 2:15 a.m.

5.3

CVSS3.1

CVE-2024-27763 -

XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST environment variable.

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: March 12, 2025, 6:15 p.m.

8.8

CVSS3.1

CVE-2025-26260 -

Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 2, 2025, 3:55 p.m.

5.5

CVSS3.1

CVE-2025-21845 - mtd: spi-nor: sst: Fix SST write failure

In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: sst: Fix SST write failure 'commit 18bcb4aa54ea ("mtd: spi-nor: sst: Factor out common write operation to `sst_nor_write_data()`")' introduced a bug where only one byte of data is written, regardless of the number o…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

3.3

CVSS3.1

CVE-2025-21860 - mm/zswap: fix inconsistency when zswap_store_page() fails

In the Linux kernel, the following vulnerability has been resolved: mm/zswap: fix inconsistency when zswap_store_page() fails Commit b7c0ccdfbafd ("mm: zswap: support large folios in zswap_store()") skips charging any zswap entries when it failed to zswap the entire folio. However, when some bas…

πŸ“… Published: March 12, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:22 a.m.
Total resulsts: 343924
Page 5839 of 34,393
Β« previous page Β» next page
Filters