5.5

CVSS3.1

CVE-2024-57997 - wifi: wcn36xx: fix channel survey memory allocation size

In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix channel survey memory allocation size KASAN reported a memory allocation issue in wcn->chan_survey due to incorrect size calculation. This commit uses kcalloc to allocate memory for wcn->chan_survey, ensuring pโ€ฆ

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

4.7

CVSS3.1

CVE-2024-57974 - udp: Deal with race between UDP socket address change and rehash

In the Linux kernel, the following vulnerability has been resolved: udp: Deal with race between UDP socket address change and rehash If a UDP socket changes its local address while it's receiving datagrams, as a result of connect(), there is a period during which a lookup operation might fail to โ€ฆ

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 23, 2025, 6 p.m.

5.5

CVSS3.1

CVE-2024-52557 - drm: zynqmp_dp: Fix integer overflow in zynqmp_dp_rate_get()

In the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_dp: Fix integer overflow in zynqmp_dp_rate_get() This patch fixes a potential integer overflow in the zynqmp_dp_rate_get() The issue comes up when the expression drm_dp_bw_code_to_link_rate(dp->test.bw_code) * 10000 โ€ฆ

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:17 p.m.

7.0

CVSS3.1

CVE-2025-21718 - net: rose: fix timer races against user threads

In the Linux kernel, the following vulnerability has been resolved: net: rose: fix timer races against user threads Rose timers only acquire the socket spinlock, without checking if the socket is owned by one user thread. Add a check and rearm the timers if needed. BUG: KASAN: slab-use-after-frโ€ฆ

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2025-21750 - wifi: brcmfmac: Check the return value of of_property_read_string_index()

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Check the return value of of_property_read_string_index() Somewhen between 6.10 and 6.11 the driver started to crash on my MacBookPro14,3. The property doesn't exist and 'tmp' remains uninitialized, so we pass a rโ€ฆ

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Jan. 2, 2026, 3:28 p.m.

5.5

CVSS3.1

CVE-2024-58022 - mailbox: th1520: Fix a NULL vs IS_ERR() bug

In the Linux kernel, the following vulnerability has been resolved: mailbox: th1520: Fix a NULL vs IS_ERR() bug The devm_ioremap() function doesn't return error pointers, it returns NULL. Update the error checking to match.

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2024-57993 - HID: hid-thrustmaster: Fix warning in thrustmaster_probe by adding endpoint check

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: Fix warning in thrustmaster_probe by adding endpoint check syzbot has found a type mismatch between a USB pipe and the transfer endpoint, which is triggered by the hid-thrustmaster driver[1]. There is a numโ€ฆ

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.5

CVSS3.1

CVE-2024-57988 - Bluetooth: btbcm: Fix NULL deref in btbcm_get_board_name()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btbcm: Fix NULL deref in btbcm_get_board_name() devm_kstrdup() can return a NULL pointer on failure,but this returned value in btbcm_get_board_name() is not checked. Add NULL check in btbcm_get_board_name(), to handle โ€ฆ

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2025-21769 - ptp: vmclock: Add .owner to vmclock_miscdev_fops

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: Add .owner to vmclock_miscdev_fops Without the .owner field, the module can be unloaded while /dev/vmclock0 is open, leading to an oops.

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

8.1

CVSS3.1

CVE-2025-25477 -

A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.

๐Ÿ“… Published: Feb. 27, 2025, midnight ๐Ÿ”„ Last Modified: July 9, 2025, 7:30 p.m.
Total resulsts: 342301
Page 5854 of 34,231
ยซ previous page ยป next page
Filters