4.4

CVSS3.1

CVE-2024-42114 - wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values syzbot is able to trigger softlockups, setting NL80211_ATTR_TXQ_QUANTUM to 2^31. We had a similar issue in sch_fq, fixed with commit d9e15a273306 ("pkt_sched: fq: do not a…

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

9.8

CVSS3.1

CVE-2024-39011 -

Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the function mergeObjects.

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:27 a.m.

7.5

CVSS3.1

CVE-2024-42225 - wifi: mt76: replace skb_put with skb_put_zero

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-42223 - media: dvb-frontends: tda10048: Fix integer overflow

In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: tda10048: Fix integer overflow state->xtal_hz can be up to 16M, so it can overflow a 32 bit integer when multiplied by pll_mfactor. Create a new 64 bit variable to hold the calculations.

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

4.7

CVSS3.1

CVE-2024-42152 - nvmet: fix a possible leak when destroy a ctrl during qp establishment

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we know that a ctrl was allocated (in the admin connect request handler) and we need to re…

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-42129 - leds: mlxreg: Use devm_mutex_init() for mutex initialization

In the Linux kernel, the following vulnerability has been resolved: leds: mlxreg: Use devm_mutex_init() for mutex initialization In this driver LEDs are registered using devm_led_classdev_register() so they are automatically unregistered after module's remove() is done. led_classdev_unregister() …

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:51 a.m.

5.5

CVSS3.1

CVE-2024-42151 - bpf: mark bpf_dummy_struct_ops.test_1 parameter as nullable

In the Linux kernel, the following vulnerability has been resolved: bpf: mark bpf_dummy_struct_ops.test_1 parameter as nullable Test case dummy_st_ops/dummy_init_ret_value passes NULL as the first parameter of the test_1() function. Mark this parameter as nullable to make verifier aware of such p…

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:24 a.m.

7.8

CVSS3.1

CVE-2024-42136 - cdrom: rearrange last_media_change check to avoid unintentional overflow

In the Linux kernel, the following vulnerability has been resolved: cdrom: rearrange last_media_change check to avoid unintentional overflow When running syzkaller with the newly reintroduced signed integer wrap sanitizer we encounter this splat: [ 366.015950] UBSAN: signed-integer-overflow in …

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: March 24, 2026, 2:46 p.m.

4.4

CVSS3.1

CVE-2024-42154 - tcp_metrics: validate source addr length

In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4 is at least 4 bytes long, and the policy doesn't have an entry for this attribute at all (neither does it for IPv6 but v6 is …

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

9.8

CVSS3.1

CVE-2024-36572 -

Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

πŸ“… Published: July 30, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:22 a.m.
Total resulsts: 349182
Page 9008 of 34,919
Β« previous page Β» next page
Filters