7.0

CVSS3.1

CVE-2025-40074 - ipv4: start using dst_dev_rcu()

In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), ipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-60805 -

An issue was discovered in BESSystem BES Application Server thru 9.5.x allowing unauthorized attackers to gain sensitive information via the "pre-resource" option in bes-web.xml.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.5

CVSS3.1

CVE-2025-61106 - frr: NULL pointer dereference in show_vty_ext_pref_pref_sid() in ospf_ext.c

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:50 p.m.

9.8

CVSS3.1

CVE-2025-60355 -

zhangyd-c OneBlog before 2.3.9 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40078 - bpf: Explicitly check accesses to bpf_sock_addr

In the Linux kernel, the following vulnerability has been resolved: bpf: Explicitly check accesses to bpf_sock_addr Syzkaller found a kernel warning on the following sock_addr program: 0: r0 = 0 1: r2 = *(u32 *)(r1 +60) 2: exit which triggers: verifier bug: error during ctx acc…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40076 - PCI: rcar-host: Pass proper IRQ domain to generic_handle_domain_irq()

In the Linux kernel, the following vulnerability has been resolved: PCI: rcar-host: Pass proper IRQ domain to generic_handle_domain_irq() Starting with commit dd26c1a23fd5 ("PCI: rcar-host: Switch to msi_create_parent_irq_domain()"), the MSI parent IRQ domain is NULL because the object of type st…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40060 - coresight: trbe: Return NULL pointer for allocation failures

In the Linux kernel, the following vulnerability has been resolved: coresight: trbe: Return NULL pointer for allocation failures When the TRBE driver fails to allocate a buffer, it currently returns the error code "-ENOMEM". However, the caller etm_setup_aux() only checks for a NULL pointer, so i…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.0

CVSS3.1

CVE-2025-40058 - iommu/vt-d: Disallow dirty tracking if incoherent page walk

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Disallow dirty tracking if incoherent page walk Dirty page tracking relies on the IOMMU atomically updating the dirty bit in the paging-structure entry. For this operation to succeed, the paging- structure memory must…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

7.0

CVSS3.1

CVE-2025-40053 - net: dlink: handle copy_thresh allocation failure

In the Linux kernel, the following vulnerability has been resolved: net: dlink: handle copy_thresh allocation failure The driver did not handle failure of `netdev_alloc_skb_ip_align()`. If the allocation failed, dereferencing `skb->protocol` could lead to a NULL pointer dereference. This patch t…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40036 - misc: fastrpc: fix possible map leak in fastrpc_put_args

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix possible map leak in fastrpc_put_args copy_to_user() failure would cause an early return without cleaning up the fdlist, which has been updated by the DSP. This could lead to map leak. Fix this by redirecting t…

πŸ“… Published: Oct. 28, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 3:05 p.m.
Total resulsts: 316893
Page 96 of 31,690
Β« previous page Β» next page
Filters