7.8

CVSS3.1

CVE-2025-21724 - iommufd/iova_bitmap: Fix shift-out-of-bounds in iova_bitmap_offset_to_index()

In the Linux kernel, the following vulnerability has been resolved: iommufd/iova_bitmap: Fix shift-out-of-bounds in iova_bitmap_offset_to_index() Resolve a UBSAN shift-out-of-bounds issue in iova_bitmap_offset_to_index() where shifting the constant "1" (of type int) by bitmap->mapped.pgshift (an …

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.8

CVSS3.1

CVE-2025-21714 - RDMA/mlx5: Fix implicit ODP use after free

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix implicit ODP use after free Prevent double queueing of implicit ODP mr destroy work by using __xa_cmpxchg() to make sure this is the only time we are destroying this specific mr. Without this change, we could try …

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:19 a.m.

5.5

CVSS3.1

CVE-2024-58016 - safesetid: check size of policy writes

In the Linux kernel, the following vulnerability has been resolved: safesetid: check size of policy writes syzbot attempts to write a buffer with a large size to a sysfs entry with writes handled by handle_policy_update(), triggering a warning in kmalloc. Check the size specified for write buffe…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

7.8

CVSS3.1

CVE-2024-58003 - media: i2c: ds90ub9x3: Fix extra fwnode_handle_put()

In the Linux kernel, the following vulnerability has been resolved: media: i2c: ds90ub9x3: Fix extra fwnode_handle_put() The ub913 and ub953 drivers call fwnode_handle_put(priv->sd.fwnode) as part of their remove process, and if the driver is removed multiple times, eventually leads to put "overf…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 1:04 p.m.

5.5

CVSS3.1

CVE-2024-58000 - io_uring: prevent reg-wait speculations

In the Linux kernel, the following vulnerability has been resolved: io_uring: prevent reg-wait speculations With *ENTER_EXT_ARG_REG instead of passing a user pointer with arguments for the waiting loop the user can specify an offset into a pre-mapped region of memory, in which case the [offset, o…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 5:48 p.m.

5.5

CVSS3.1

CVE-2024-57991 - wifi: rtw89: chan: fix soft lockup in rtw89_entity_recalc_mgnt_roles()

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: chan: fix soft lockup in rtw89_entity_recalc_mgnt_roles() During rtw89_entity_recalc_mgnt_roles(), there is a normalizing process which will re-order the list if an entry with target pattern is found. And once one is…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

7.8

CVSS3.1

CVE-2024-57983 - mailbox: th1520: Fix memory corruption due to incorrect array size

In the Linux kernel, the following vulnerability has been resolved: mailbox: th1520: Fix memory corruption due to incorrect array size The functions th1520_mbox_suspend_noirq and th1520_mbox_resume_noirq are intended to save and restore the interrupt mask registers in the MBOX ICU0. However, the …

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2024-57953 - rtc: tps6594: Fix integer overflow on 32bit systems

In the Linux kernel, the following vulnerability has been resolved: rtc: tps6594: Fix integer overflow on 32bit systems The problem is this multiply in tps6594_rtc_set_offset() tmp = offset * TICKS_PER_HOUR; The "tmp" variable is an s64 but "offset" is a long in the (-277774)-277774 range. On…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:18 p.m.

5.5

CVSS3.1

CVE-2024-57852 - firmware: qcom: scm: smc: Handle missing SCM device

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: smc: Handle missing SCM device Commit ca61d6836e6f ("firmware: qcom: scm: fix a NULL-pointer dereference") makes it explicit that qcom_scm_get_tzmem_pool() can return NULL, therefore its users should handle t…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 23, 2025, 1:04 p.m.

5.5

CVSS3.1

CVE-2024-52559 - drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()

In the Linux kernel, the following vulnerability has been resolved: drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit() The "submit->cmd[i].size" and "submit->cmd[i].offset" variables are u32 values that come from the user via the submit_lookup_cmds() function. This addition could lea…

πŸ“… Published: Feb. 27, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 8:17 p.m.
Total resulsts: 349182
Page 6546 of 34,919
Β« previous page Β» next page
Filters