7.0

CVSS3.1

CVE-2025-68800 - mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats Cited commit added a dedicated mutex (instead of RTNL) to protect the multicast route list, so that it will not change while the driver periodically trave…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

7.0

CVSS3.1

CVE-2025-71093 - e1000: fix OOB in e1000_tbi_should_accept()

In the Linux kernel, the following vulnerability has been resolved: e1000: fix OOB in e1000_tbi_should_accept() In e1000_tbi_should_accept() we read the last byte of the frame via 'data[length - 1]' to evaluate the TBI workaround. If the descriptor- reported length is zero or larger than the actu…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

0.0

CVE-2025-68809 - ksmbd: vfs: fix race on m_flags in vfs_cache

In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in vfs_cache ksmbd maintains delete-on-close and pending-delete state in ksmbd_inode->m_flags. In vfs_cache.c this field is accessed under inconsistent locking: some paths read and modify m_flags u…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 14, 2026, 4:26 p.m.

0.0

CVE-2025-68805 - fuse: fix io-uring list corruption for terminated non-committed requests

In the Linux kernel, the following vulnerability has been resolved: fuse: fix io-uring list corruption for terminated non-committed requests When a request is terminated before it has been committed, the request is not removed from the queue's list. This leaves a dangling list entry that leads to…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 14, 2026, 4:26 p.m.

5.5

CVSS3.1

CVE-2025-68794 - iomap: adjust read range correctly for non-block-aligned positions

In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-aligned positions iomap_adjust_read_range() assumes that the position and length passed in are block-aligned. This is not always the case however, as shown in the syzbot generated …

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 14, 2026, 4:26 p.m.

7.5

CVSS3.1

CVE-2025-71026 -

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 6:23 p.m.

7.5

CVSS3.1

CVE-2025-71025 -

Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 6:24 p.m.

5.5

CVSS3.1

CVE-2025-71096 - RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly The netlink response for RDMA_NL_LS_OP_IP_RESOLVE should always have a LS_NLA_TYPE_DGID attribute, it is invalid if it does not. Use the nl parsing logic properly a…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

5.5

CVSS3.1

CVE-2025-68820 - ext4: xattr: fix null pointer deref in ext4_raw_inode()

In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED), iloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all() lacks error checking, this will lead …

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

7.0

CVSS3.1

CVE-2025-68819 - media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()

In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() rlen value is a user-controlled value, but dtv5100_i2c_msg() does not check the size of the rlen value. Therefore, if it is set to a value larger than sizeof(st->dat…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.
Total resulsts: 327935
Page 78 of 32,794
Β« previous page Β» next page
Filters