7.1

CVSS3.1

CVE-2025-21789 - LoongArch: csum: Fix OoB access in IP checksum code for negative lengths

In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit system") would cause an undefined shift and an out-of-bounds read. Commit 8bd795fedb8…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2024-52560 - fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr() Extended the `mi_enum_attr()` function interface with an additional parameter, `struct ntfs_inode *ni`, to allow marking the inode as bad as soon as an error…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 1:05 p.m.

7.5

CVSS3.1

CVE-2024-41336 -

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Feb. 28, 2025, 5:15 p.m.

7.1

CVSS3.1

CVE-2025-21741 - usbnet: ipheth: fix DPE OoB read

In the Linux kernel, the following vulnerability has been resolved: usbnet: ipheth: fix DPE OoB read Fix an out-of-bounds DPE read, limit the number of processed DPEs to the amount that fits into the fixed-size NDP16 header.

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

7.8

CVSS3.1

CVE-2025-21739 - scsi: ufs: core: Fix use-after free in init error and remove paths

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix use-after free in init error and remove paths devm_blk_crypto_profile_init() registers a cleanup handler to run when the associated (platform-) device is being released. For UFS, the crypto private data and p…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:20 a.m.

5.5

CVSS3.1

CVE-2024-58001 - ocfs2: handle a symlink read error correctly

In the Linux kernel, the following vulnerability has been resolved: ocfs2: handle a symlink read error correctly Patch series "Convert ocfs2 to use folios". Mark did a conversion of ocfs2 to use folios and sent it to me as a giant patch for review ;-) So I've redone it as individual patches, an…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:56 a.m.

9.8

CVSS3.1

CVE-2024-55160 -

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 5:45 p.m.

7.8

CVSS3.1

CVE-2025-21714 - RDMA/mlx5: Fix implicit ODP use after free

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix implicit ODP use after free Prevent double queueing of implicit ODP mr destroy work by using __xa_cmpxchg() to make sure this is the only time we are destroying this specific mr. Without this change, we could try …

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:19 a.m.

5.5

CVSS3.1

CVE-2024-58019 - nvkm/gsp: correctly advance the read pointer of GSP message queue

In the Linux kernel, the following vulnerability has been resolved: nvkm/gsp: correctly advance the read pointer of GSP message queue A GSP event message consists three parts: message header, RPC header, message body. GSP calculates the number of pages to write from the total size of a GSP messag…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 8:41 p.m.

7.8

CVSS3.1

CVE-2025-21735 - NFC: nci: Add bounds checking in nci_hci_create_pipe()

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corruption in the caller, nci_hci_connect_gate().

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.
Total resulsts: 342272
Page 5856 of 34,228
Β« previous page Β» next page
Filters