7.0

CVSS3.1

CVE-2025-38623 - PCI: pnv_php: Fix surprise plug detection and recovery

In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Fix surprise plug detection and recovery The existing PowerNV hotplug code did not handle surprise plug events correctly, leading to a complete failure of the hotplug system after device removal and a required reboo…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-38663 - nilfs2: reject invalid file types when reading inodes

In the Linux kernel, the following vulnerability has been resolved: nilfs2: reject invalid file types when reading inodes To prevent inodes with invalid file types from tripping through the vfs and causing malfunctions or assertion failures, add a missing sanity check when reading an inode from a…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-38652 - f2fs: fix to avoid out-of-boundary access in devs.path

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in devs.path - touch /mnt/f2fs/012345678901234567890123456789012345678901234567890123 - truncate -s $((1024*1024*1024)) \ /mnt/f2fs/01234567890123456789012345678901234567890123456789012…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

7.0

CVSS3.1

CVE-2025-38645 - net/mlx5: Check device memory pointer before usage

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Check device memory pointer before usage Add a NULL check before accessing device memory to prevent a crash if dev->dm allocation in mlx5_init_once() fails.

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-38639 - netfilter: xt_nfacct: don't assume acct name is null-terminated

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_nfacct: don't assume acct name is null-terminated BUG: KASAN: slab-out-of-bounds in .. lib/vsprintf.c:721 Read of size 1 at addr ffff88801eac95c8 by task syz-executor183/5851 [..] string+0x231/0x2b0 lib/vsprintf.c:…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-38635 - clk: davinci: Add NULL check in davinci_lpsc_clk_register()

In the Linux kernel, the following vulnerability has been resolved: clk: davinci: Add NULL check in davinci_lpsc_clk_register() devm_kasprintf() returns NULL when memory allocation fails. Currently, davinci_lpsc_clk_register() does not check for this case, which results in a NULL pointer derefere…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-38634 - power: supply: cpcap-charger: Fix null check for power_supply_get_by_name

In the Linux kernel, the following vulnerability has been resolved: power: supply: cpcap-charger: Fix null check for power_supply_get_by_name In the cpcap_usb_detect() function, the power_supply_get_by_name() function may return `NULL` instead of an error pointer. To prevent potential null pointe…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

7.0

CVSS3.1

CVE-2025-38618 - vsock: Do not allow binding to VMADDR_PORT_ANY

In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to autobind to VMADDR_PORT_ANY. This can cause a use-after-free when a connection is made to the bound socket. The socket returned by accept() also has por…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2025-38624 - PCI: pnv_php: Clean up allocated IRQs on unplug

In the Linux kernel, the following vulnerability has been resolved: PCI: pnv_php: Clean up allocated IRQs on unplug When the root of a nested PCIe bridge configuration is unplugged, the pnv_php driver leaked the allocated IRQ resources for the child bridges' hotplug event notifications, resulting…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.

7.0

CVSS3.1

CVE-2025-38622 - net: drop UFO packets in udp_rcv_segment()

In the Linux kernel, the following vulnerability has been resolved: net: drop UFO packets in udp_rcv_segment() When sending a packet with virtio_net_hdr to tun device, if the gso_type in virtio_net_hdr is SKB_GSO_UDP and the gso_size is less than udphdr size, below crash may happen. ----------…

πŸ“… Published: Aug. 22, 2025, midnight πŸ”„ Last Modified: Aug. 28, 2025, 3:15 p.m.
Total resulsts: 307401
Page 82 of 30,741
Β« previous page Β» next page
Filters