5.5

CVSS3.1

CVE-2024-40972 - ext4: do not create EA inode under buffer lock

In the Linux kernel, the following vulnerability has been resolved: ext4: do not create EA inode under buffer lock ext4_xattr_set_entry() creates new EA inodes while holding buffer lock on the external xattr block. This is problematic as it nests all the allocation locking (which acquires locks o…

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

6.3

CVSS3.1

CVE-2024-40918 - parisc: Try to fix random segmentation faults in package builds

In the Linux kernel, the following vulnerability has been resolved: parisc: Try to fix random segmentation faults in package builds PA-RISC systems with PA8800 and PA8900 processors have had problems with random segmentation faults for many years. Systems with earlier processors are much more st…

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:36 a.m.

5.5

CVSS3.1

CVE-2024-40928 - net: ethtool: fix the error condition in ethtool_get_phy_stats_ethtool()

In the Linux kernel, the following vulnerability has been resolved: net: ethtool: fix the error condition in ethtool_get_phy_stats_ethtool() Clang static checker (scan-build) warning: net/ethtool/ioctl.c:line 2233, column 2 Called function pointer is null (null dereference). Return '-EOPNOTSUPP'…

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Jan. 19, 2026, 12:17 p.m.

5.5

CVSS3.1

CVE-2024-40912 - wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup()

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Fix deadlock in ieee80211_sta_ps_deliver_wakeup() The ieee80211_sta_ps_deliver_wakeup() function takes sta->ps_lock to synchronizes with ieee80211_tx_h_unicast_ps_buf() which is called from softirq context. Howeve…

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

7.8

CVSS3.1

CVE-2024-40996 - bpf: Avoid splat in pskb_pull_reason

In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid splat in pskb_pull_reason syzkaller builds (CONFIG_DEBUG_NET=y) frequently trigger a debug hint in pskb_may_pull. We'd like to retain this debug check because it might hint at integer overflows and other issues (kerne…

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-40973 - media: mtk-vcodec: potential null pointer deference in SCP

In the Linux kernel, the following vulnerability has been resolved: media: mtk-vcodec: potential null pointer deference in SCP The return value of devm_kzalloc() needs to be checked to avoid NULL pointer deference. This is similar to CVE-2022-3113.

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

7.8

CVSS3.1

CVE-2024-40989 - KVM: arm64: Disassociate vcpus from redistributor region on teardown

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Disassociate vcpus from redistributor region on teardown When tearing down a redistributor region, make sure we don't have any dangling pointer to that region stored in a vcpu.

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-40966 - tty: add the option to have a tty reject a new ldisc

In the Linux kernel, the following vulnerability has been resolved: tty: add the option to have a tty reject a new ldisc ... and use it to limit the virtual terminals to just N_TTY. They are kind of special, and in particular, the "con_write()" routine violates the "writes cannot sleep" rule tha…

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:36 a.m.

5.5

CVSS3.1

CVE-2024-40921 - net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state Pass the already obtained vlan group pointer to br_mst_vlan_set_state() instead of dereferencing it again. Each caller has already correctly dereferenced it for …

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

7.2

CVSS3.1

CVE-2024-40545 -

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

πŸ“… Published: July 12, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:31 a.m.
Total resulsts: 343928
Page 8647 of 34,393
Β« previous page Β» next page
Filters