5.5

CVSS3.1

CVE-2024-46824 - iommufd: Require drivers to supply the cache_invalidate_user ops

In the Linux kernel, the following vulnerability has been resolved: iommufd: Require drivers to supply the cache_invalidate_user ops If drivers don't do this then iommufd will oops invalidation ioctls with something like: Unable to handle kernel NULL pointer dereference at virtual address 0000…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:35 a.m.

5.5

CVSS3.1

CVE-2024-46822 - arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry

In the Linux kernel, the following vulnerability has been resolved: arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry In a review discussion of the changes to support vCPU hotplug where a check was added on the GICC being enabled if was online, it was noted that there is need to…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: Dec. 20, 2025, 8:51 a.m.

4.7

CVSS3.1

CVE-2024-46851 - drm/amd/display: Avoid race between dcn10_set_drr() and dc_state_destruct()

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid race between dcn10_set_drr() and dc_state_destruct() dc_state_destruct() nulls the resource context of the DC state. The pipe context passed to dcn10_set_drr() is a member of this resource context. If dc_s…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:35 a.m.

5.5

CVSS3.1

CVE-2024-46843 - scsi: ufs: core: Remove SCSI host only if added

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove SCSI host only if added If host tries to remove ufshcd driver from a UFS device it would cause a kernel panic if ufshcd_async_scan fails during ufshcd_probe_hba before adding a SCSI host with scsi_add_host…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 21, 2025, 9:13 a.m.

6.3

CVSS3.1

CVE-2024-46257 -

A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: June 3, 2025, 11:55 a.m.

5.5

CVSS3.1

CVE-2024-46847 - mm: vmalloc: ensure vmap_block is initialised before adding to queue

In the Linux kernel, the following vulnerability has been resolved: mm: vmalloc: ensure vmap_block is initialised before adding to queue Commit 8c61291fd850 ("mm: fix incorrect vbq reference in purge_fragmented_block") extended the 'vmap_block' structure to contain a 'cpu' field which is set at a…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 12:58 p.m.

8.8

CVSS3.1

CVE-2024-46366 -

A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: July 9, 2025, 5:57 p.m.

9.8

CVSS3.1

CVE-2024-46256 -

A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: June 3, 2025, 11:55 a.m.

5.5

CVSS3.1

CVE-2024-46867 - drm/xe/client: fix deadlock in show_meminfo()

In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: fix deadlock in show_meminfo() There is a real deadlock as well as sleeping in atomic() bug in here, if the bo put happens to be the last ref, since bo destruction wants to grab the same spinlock and sleeping locks…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:36 a.m.

5.5

CVSS3.1

CVE-2024-46857 - net/mlx5: Fix bridge mode operations when there are no VFs

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix bridge mode operations when there are no VFs Currently, trying to set the bridge mode attribute when numvfs=0 leads to a crash: bridge link set dev eth2 hwmode vepa [ 168.967392] BUG: kernel NULL pointer derefere…

πŸ“… Published: Sept. 27, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.
Total resulsts: 349182
Page 8452 of 34,919
Β« previous page Β» next page
Filters