5.5

CVSS3.1

CVE-2024-53163 - crypto: qat/qat_420xx - fix off by one in uof_get_name()

In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_420xx - fix off by one in uof_get_name() This is called from uof_get_name_420xx() where "num_objs" is the ARRAY_SIZE() of fw_objs[]. The > needs to be >= to prevent an out of bounds access.

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.

4.7

CVSS3.1

CVE-2024-53160 - rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu

In the Linux kernel, the following vulnerability has been resolved: rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu KCSAN reports a data race when access the krcp->monitor_work.timer.expires variable in the schedule_delayed_monitor_work() function: <snip> BUG: KCSAN: data-race in __mo…

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.

5.5

CVSS3.1

CVE-2024-53158 - soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get() This loop is supposed to break if the frequency returned from clk_round_rate() is the same as on the previous iteration. However, that check doesn't make sense on …

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

7.8

CVSS3.1

CVE-2024-53156 - wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() I found the following bug in my fuzzer: UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath9k/htc_hst.c:26:51 index 255 is out of range for…

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.5

CVSS3.1

CVE-2024-53152 - PCI: tegra194: Move controller cleanups to pex_ep_event_pex_rst_deassert()

In the Linux kernel, the following vulnerability has been resolved: PCI: tegra194: Move controller cleanups to pex_ep_event_pex_rst_deassert() Currently, the endpoint cleanup function dw_pcie_ep_cleanup() and EPF deinit notify function pci_epc_deinit_notify() are called during the execution of pe…

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Oct. 8, 2025, 2:43 p.m.

5.5

CVSS3.1

CVE-2024-53145 - um: Fix potential integer overflow during physmem setup

In the Linux kernel, the following vulnerability has been resolved: um: Fix potential integer overflow during physmem setup This issue happens when the real map size is greater than LONG_MAX, which can be easily triggered on UML/i386.

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.5

CVSS3.1

CVE-2024-53154 - clk: clk-apple-nco: Add NULL check in applnco_probe

In the Linux kernel, the following vulnerability has been resolved: clk: clk-apple-nco: Add NULL check in applnco_probe Add NULL check in applnco_probe, to handle kernel NULL pointer dereference error.

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

5.6

CVSS3.1

CVE-2024-56827 - Openjpeg: heap buffer overflow in lib/openjp2/j2k.c

A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2025, 10:33 p.m.

5.6

CVSS3.1

CVE-2024-56826 - Openjpeg: heap buffer overflow in bin/common/color.c

A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are specified while using the opj_decompress utility. This can lead to an application crash or other undefined behavior.

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 6, 2025, 10:33 p.m.

5.5

CVSS3.1

CVE-2024-53161 - EDAC/bluefield: Fix potential integer overflow

In the Linux kernel, the following vulnerability has been resolved: EDAC/bluefield: Fix potential integer overflow The 64-bit argument for the "get DIMM info" SMC call consists of mem_ctrl_idx left-shifted 16 bits and OR-ed with DIMM index. With mem_ctrl_idx defined as 32-bits wide the left-shif…

πŸ“… Published: Dec. 24, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.
Total resulsts: 343887
Page 6859 of 34,389
Β« previous page Β» next page
Filters