5.5

CVSS3.1

CVE-2023-52936 - kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup()

In the Linux kernel, the following vulnerability has been resolved: kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() When calling debugfs_lookup() the result must have dput() called on it, otherwise the memory will leak over time. To make things simpler, just call debugfs_look…

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:17 p.m.

7.8

CVSS3.1

CVE-2023-52931 - drm/i915: Avoid potential vm use-after-free

In the Linux kernel, the following vulnerability has been resolved: drm/i915: Avoid potential vm use-after-free Adding the vm to the vm_xa table makes it visible to userspace, which could try to race with us to close the vm. So we need to take our extra reference before putting it in the table. …

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:46 a.m.

5.5

CVSS3.1

CVE-2023-52929 - nvmem: core: fix cleanup after dev_set_name()

In the Linux kernel, the following vulnerability has been resolved: nvmem: core: fix cleanup after dev_set_name() If dev_set_name() fails, we leak nvmem->wp_gpio as the cleanup does not put this. While a minimal fix for this would be to add the gpiod_put() call, we can do better if we split devic…

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: Oct. 28, 2025, 6:30 p.m.

7.8

CVSS3.1

CVE-2022-49761 - btrfs: always report error in run_one_delayed_ref()

In the Linux kernel, the following vulnerability has been resolved: btrfs: always report error in run_one_delayed_ref() Currently we have a btrfs_debug() for run_one_delayed_ref() failure, but if end users hit such problem, there will be no chance that btrfs_debug() is enabled. This can lead to …

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: Dec. 23, 2025, 1:25 p.m.

5.5

CVSS3.1

CVE-2022-49757 - EDAC/highbank: Fix memory leak in highbank_mc_probe()

In the Linux kernel, the following vulnerability has been resolved: EDAC/highbank: Fix memory leak in highbank_mc_probe() When devres_open_group() fails, it returns -ENOMEM without freeing memory allocated by edac_mc_alloc(). Call edac_mc_free() on the error handling path to avoid a memory leak.…

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:15 p.m.

7.8

CVSS3.1

CVE-2022-49755 - usb: gadget: f_fs: Prevent race during ffs_ep0_queue_wait

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Prevent race during ffs_ep0_queue_wait While performing fast composition switch, there is a possibility that the process of ffs_ep0_write/ffs_ep0_read get into a race condition due to ep0req being freed up from…

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 8:44 a.m.

5.5

CVSS3.1

CVE-2022-49751 - w1: fix WARNING after calling w1_process()

In the Linux kernel, the following vulnerability has been resolved: w1: fix WARNING after calling w1_process() I got the following WARNING message while removing driver(ds2482): ------------[ cut here ]------------ do not call blocking ops when !TASK_RUNNING; state=1 set at [<000000002d50bfb6>] …

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:17 p.m.

5.5

CVSS3.1

CVE-2022-49749 - i2c: designware: use casting of u64 in clock multiplication to avoid overflow

In the Linux kernel, the following vulnerability has been resolved: i2c: designware: use casting of u64 in clock multiplication to avoid overflow In functions i2c_dw_scl_lcnt() and i2c_dw_scl_hcnt() may have overflow by depending on the values of the given parameters including the ic_clk. For exa…

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:15 p.m.

5.5

CVSS3.1

CVE-2022-49748 - perf/x86/amd: fix potential integer overflow on shift of a int

In the Linux kernel, the following vulnerability has been resolved: perf/x86/amd: fix potential integer overflow on shift of a int The left shift of int 32 bit integer constant 1 is evaluated using 32 bit arithmetic and then passed as a 64 bit function argument. In the case where i is 32 or more …

πŸ“… Published: March 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:15 p.m.

4.3

CVSS3.1

CVE-2025-20230 - Missing Access Control and Incorrect Ownership of Data in App Key Value Store (KVStore) collections…

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the β€œadminβ€œ or β€œpowerβ€œ Splunk roles could edit and delete other user data in App Key Value Sto…

πŸ“… Published: March 26, 2025, 10:24 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 6:01 p.m.
Total resulsts: 346624
Page 5942 of 34,663
Β« previous page Β» next page
Filters