7.8

CVSS3.1

CVE-2024-41042 - netfilter: nf_tables: prefer nft_chain_validate

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: prefer nft_chain_validate nft_chain_validate already performs loop detection because a cycle will result in a call stack overflow (ctx->level >= NFT_JUMP_STACK_SIZE). It also follows maps via ->validate calโ€ฆ

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-42069 - net: mana: Fix possible double free in error handling path

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function adev_release calls kfree(madev). We shouldn't call kfree(madev) agaiโ€ฆ

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.5

CVSS3.1

CVE-2024-41055 - mm: prevent derefencing NULL ptr in pfn_section_valid()

In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 ("mm/sparsemem: fix race in accessing memory_section->usage") changed pfn_section_valid() to add a READ_ONCE() call around "ms->usage" to fix a race withโ€ฆ

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-42067 - bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()

In the Linux kernel, the following vulnerability has been resolved: bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro() set_memory_rox() can fail, leaving memory unprotected. Check return and bail out when bpf_jit_binary_lock_ro() returns an error.

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 10:51 a.m.

5.5

CVSS3.1

CVE-2024-41030 - ksmbd: discard write access to the directory open

In the Linux kernel, the following vulnerability has been resolved: ksmbd: discard write access to the directory open may_open() does not allow a directory to be opened with the write access. However, some writing flags set by client result in adding write access on server, making ksmbd incompatiโ€ฆ

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-41083 - netfs: Fix netfs_page_mkwrite() to check folio->mapping is valid

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_page_mkwrite() to check folio->mapping is valid Fix netfs_page_mkwrite() to check that folio->mapping is valid once it has taken the folio lock (as filemap_page_mkwrite() does). Without this, generic/247 occasioโ€ฆ

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: May 4, 2025, 9:21 a.m.

8.8

CVSS3.1

CVE-2024-37857 -

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: April 23, 2025, 2:35 p.m.

5.5

CVSS3.1

CVE-2024-41081 - ila: block BH in ila_output()

In the Linux kernel, the following vulnerability has been resolved: ila: block BH in ila_output() As explained in commit 1378817486d6 ("tipc: block BH before using dst_cache"), net/core/dst_cache.c helpers need to be called with BH disabled. ila_output() is called from lwtunnel_output() possiblyโ€ฆ

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-41072 - wifi: cfg80211: wext: add extra SIOCSIWSCAN data check

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: wext: add extra SIOCSIWSCAN data check In 'cfg80211_wext_siwscan()', add extra check whether number of channels passed via 'ioctl(sock, SIOCSIWSCAN, ...)' doesn't exceed IW_MAX_FREQUENCIES and reject invalid requeโ€ฆ

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 10:37 a.m.

5.5

CVSS3.1

CVE-2024-41065 - powerpc/pseries: Whitelist dtl slub object for copying to userspace

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Whitelist dtl slub object for copying to userspace Reading the dispatch trace log from /sys/kernel/debug/powerpc/dtl/cpu-* results in a BUG() when the config CONFIG_HARDENED_USERCOPY is enabled as shown below. โ€ฆ

๐Ÿ“… Published: July 29, 2024, midnight ๐Ÿ”„ Last Modified: Jan. 5, 2026, 10:37 a.m.
Total resulsts: 346099
Page 8725 of 34,610
ยซ previous page ยป next page
Filters