5.5

CVSS3.1

CVE-2025-68820 - ext4: xattr: fix null pointer deref in ext4_raw_inode()

In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED), iloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all() lacks error checking, this will lead …

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

5.5

CVSS3.1

CVE-2025-71075 - scsi: aic94xx: fix use-after-free in device removal path

In the Linux kernel, the following vulnerability has been resolved: scsi: aic94xx: fix use-after-free in device removal path The asd_pci_remove() function fails to synchronize with pending tasklets before freeing the asd_ha structure, leading to a potential use-after-free vulnerability. When a d…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

0.0

CVE-2025-71079 - net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write

In the Linux kernel, the following vulnerability has been resolved: net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write A deadlock can occur between nfc_unregister_device() and rfkill_fop_write() due to lock ordering inversion between device_lock and rfkill_global_mutex. Th…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

0.0

CVE-2025-71081 - ASoC: stm32: sai: fix OF node leak on probe

In the Linux kernel, the following vulnerability has been resolved: ASoC: stm32: sai: fix OF node leak on probe The reference taken to the sync provider OF node when probing the platform device is currently only dropped if the set_sync() callback fails during DAI probe. Make sure to drop the ref…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

5.5

CVSS3.1

CVE-2025-71083 - drm/ttm: Avoid NULL pointer deref for evicted BOs

In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Avoid NULL pointer deref for evicted BOs It is possible for a BO to exist that is not currently associated with a resource, e.g. because it has been evicted. When devcoredump tries to read the contents of all BOs for du…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

7.0

CVSS3.1

CVE-2025-71094 - net: usb: asix: validate PHY address before use

In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: validate PHY address before use The ASIX driver reads the PHY address from the USB device via asix_read_phy_addr(). A malicious or faulty device can return an invalid address (>= PHY_MAX_ADDR), which causes a warn…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

7.0

CVSS3.1

CVE-2025-68815 - net/sched: ets: Remove drr class from the active list if it changes to strict

In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: Remove drr class from the active list if it changes to strict Whenever a user issues an ets qdisc change command, transforming a drr class into a strict one, the ets code isn't checking whether that class was in t…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:19 p.m.

7.0

CVSS3.1

CVE-2025-68803 - NFSD: NFSv4 file creation neglects setting ACL

In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds that it is only a default ACL (based on the mode bits) and not th…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 17, 2026, 3:37 p.m.

7.0

CVSS3.1

CVE-2025-71080 - ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT On PREEMPT_RT kernels, after rt6_get_pcpu_route() returns NULL, the current task can be preempted. Another task running on the same CPU may then execute rt6_make_pcpu_route…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 14, 2026, 4:26 p.m.

8.8

CVSS3.1

CVE-2025-68707 -

An authentication bypass vulnerability in the Tongyu AX1800 Wi-Fi 6 Router with firmware 1.0.0 allows unauthenticated network-adjacent attackers to perform arbitrary configuration changes without providing credentials, as long as a valid admin session is active. This can result in full compromise o…

πŸ“… Published: Jan. 13, 2026, midnight πŸ”„ Last Modified: Jan. 16, 2026, 3:15 p.m.
Total resulsts: 327938
Page 79 of 32,794
Β« previous page Β» next page
Filters