5.5

CVSS3.1

CVE-2024-35997 - HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up

In the Linux kernel, the following vulnerability has been resolved: HID: i2c-hid: remove I2C_HID_READ_PENDING flag to prevent lock-up The flag I2C_HID_READ_PENDING is used to serialize I2C operations. However, this is not necessary, because I2C core already has its own locking for that. More imp…

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:10 a.m.

5.5

CVSS3.1

CVE-2024-35980 - arm64: tlb: Fix TLBI RANGE operand

In the Linux kernel, the following vulnerability has been resolved: arm64: tlb: Fix TLBI RANGE operand KVM/arm64 relies on TLBI RANGE feature to flush TLBs when the dirty pages are collected by VMM and the page table entries become write protected during live migration. Unfortunately, the operand…

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:09 a.m.

5.6

CVSS3.1

CVE-2024-35195 - Requests `Session` object does not verify requests after making first request with verify=False

Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `ve…

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-35998 - smb3: fix lock ordering potential deadlock in cifs_sync_mid_result

In the Linux kernel, the following vulnerability has been resolved: smb3: fix lock ordering potential deadlock in cifs_sync_mid_result Coverity spotted that the cifs_sync_mid_result function could deadlock "Thread deadlock (ORDER_REVERSAL) lock_order: Calling spin_lock acquires lock TCP_Server_I…

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:36 a.m.

5.5

CVSS3.1

CVE-2024-35995 - ACPI: CPPC: Use access_width over bit_width for system memory accesses

In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Use access_width over bit_width for system memory accesses To align with ACPI 6.3+, since bit_width can be any 8-bit value, it cannot be depended on to be always on a clean 8b boundary. This was uncovered on the Cobal…

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:36 a.m.

8.1

CVSS3.1

CVE-2024-29651 - json-schema-ref-parser: Prototype pollution issue

A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to execute arbitrary code via the bundle()`, `parse()`, `resolve()`, `dereference() functions.

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-35990 - dma: xilinx_dpdma: Fix locking

In the Linux kernel, the following vulnerability has been resolved: dma: xilinx_dpdma: Fix locking There are several places where either chan->lock or chan->vchan.lock was not held. Add appropriate locking. This fixes lockdep warnings like [ 31.077578] ------------[ cut here ]------------ [ …

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:10 a.m.

5.5

CVSS3.1

CVE-2024-35994 - firmware: qcom: uefisecapp: Fix memory related IO errors and crashes

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: Fix memory related IO errors and crashes It turns out that while the QSEECOM APP_SEND command has specific fields for request and response buffers, uefisecapp expects them both to be in a single memory…

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: Sept. 23, 2025, 6:07 p.m.

5.5

CVSS3.1

CVE-2024-35973 - geneve: fix header validation in geneve[6]_xmit_skb

In the Linux kernel, the following vulnerability has been resolved: geneve: fix header validation in geneve[6]_xmit_skb syzbot is able to trigger an uninit-value in geneve_xmit() [1] Problem : While most ip tunnel helpers (like ip_tunnel_get_dsfield()) uses skb_protocol(skb, true), pskb_inet_may…

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 12:56 p.m.

5.5

CVSS3.1

CVE-2024-35972 - bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init()

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init() If ulp = kzalloc() fails, the allocated edev will leak because it is not properly assigned and the cleanup path will not be able to free it. Fix it by assigning it …

πŸ“… Published: May 20, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:09 a.m.
Total resulsts: 349182
Page 9772 of 34,919
Β« previous page Β» next page
Filters