5.5

CVSS3.1

CVE-2024-41052 - vfio/pci: Init the count variable in collecting hot-reset devices

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Init the count variable in collecting hot-reset devices The count variable is used without initialization, it results in mistakes in the device counting and crashes the userspace if the get hot reset info path is trigge…

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:21 a.m.

5.5

CVSS3.1

CVE-2024-41038 - firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers Check that all fields of a V2 algorithm header fit into the available firmware data buffer. The wmfw V2 format introduced variable-length strings in the alg…

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-41025 - misc: fastrpc: Fix memory leak in audio daemon attach operation

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix memory leak in audio daemon attach operation Audio PD daemon send the name as part of the init IOCTL call. This name needs to be copied to kernel for which memory is allocated. This memory is never freed which …

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:20 a.m.

5.5

CVSS3.1

CVE-2024-41021 - s390/mm: Fix VM_FAULT_HWPOISON handling in do_exception()

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix VM_FAULT_HWPOISON handling in do_exception() There is no support for HWPOISON, MEMORY_FAILURE, or ARCH_HAS_COPY_MC on s390. Therefore we do not expect to see VM_FAULT_HWPOISON in do_exception(). However, since commi…

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: Sept. 25, 2025, 8:05 p.m.

6.1

CVSS3.1

CVE-2024-41023 - sched/deadline: Fix task_struct reference leak

In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix task_struct reference leak During the execution of the following stress test with linux-rt: stress-ng --cyclic 30 --timeout 30 --minimize --quiet kmemleak frequently reported a memory leak concerning the tas…

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 12:57 p.m.

5.5

CVSS3.1

CVE-2024-42063 - bpf: Mark bpf prog stack with kmsan_unposion_memory in interpreter mode

In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf prog stack with kmsan_unposion_memory in interpreter mode syzbot reported uninit memory usages during map_{lookup,delete}_elem. ========== BUG: KMSAN: uninit-value in __dev_map_lookup_elem kernel/bpf/devmap.c:441 […

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:51 a.m.

5.5

CVSS3.1

CVE-2024-41062 - bluetooth/l2cap: sync sock recv cb and release

In the Linux kernel, the following vulnerability has been resolved: bluetooth/l2cap: sync sock recv cb and release The problem occurs between the system call to close the sock and hci_rx_work, where the former releases the sock and the latter accesses it without lock protection. CPU0 …

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:37 a.m.

5.5

CVSS3.1

CVE-2024-41054 - scsi: ufs: core: Fix ufshcd_clear_cmd racing issue

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix ufshcd_clear_cmd racing issue When ufshcd_clear_cmd is racing with the completion ISR, the completed tag of the request's mq_hctx pointer will be set to NULL by the ISR. And ufshcd_clear_cmd's call to ufshcd…

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:21 a.m.

5.5

CVSS3.1

CVE-2024-41079 - nvmet: always initialize cqe.result

In the Linux kernel, the following vulnerability has been resolved: nvmet: always initialize cqe.result The spec doesn't mandate that the first two double words (aka results) for the command queue entry need to be set to 0 when they are not used (not specified). Though, the target implemention re…

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: Dec. 20, 2025, 8:51 a.m.

4.7

CVSS3.1

CVE-2024-40576 -

Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" parameters in the houses page at the index.php component.

πŸ“… Published: July 29, 2024, midnight πŸ”„ Last Modified: May 6, 2025, 4:42 p.m.
Total resulsts: 346087
Page 8722 of 34,609
Β« previous page Β» next page
Filters