7.0

CVSS3.1

CVE-2025-40081 - perf: arm_spe: Prevent overflow in PERF_IDX2OFF()

In the Linux kernel, the following vulnerability has been resolved: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() Cast nr_pages to unsigned long to avoid overflow when handling large AUX buffer sizes (>= 2 GiB).

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

6

CVSS3.1

CVE-2025-12390 - Org.keycloak.protocol.oidc.endpoints.logoutendpoint: offline session takeover due to reused authent…

A flaw was found in Keycloak. In Keycloak where a user can accidentally get access to another user's session if both use the same device and browser. This happens because Keycloak sometimes reuses session identifiers and doesn’t clean up properly during logout when browser cookies are missing. As a…

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

7.0

CVSS3.1

CVE-2025-40080 - nbd: restrict sockets to TCP and UDP

In the Linux kernel, the following vulnerability has been resolved: nbd: restrict sockets to TCP and UDP Recently, syzbot started to abuse NBD with all kinds of sockets. Commit cf1b2326b734 ("nbd: verify socket is supported during setup") made sure the socket supported a shutdown() method. Expl…

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

7.0

CVSS3.1

CVE-2025-40038 - KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid Skip the WRMSR and HLT fastpaths in SVM's VM-Exit handler if the next RIP isn't valid, e.g. because KVM is running with nrips=false. SVM must decode and emulat…

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40072 - fanotify: Validate the return value of mnt_ns_from_dentry() before dereferencing

In the Linux kernel, the following vulnerability has been resolved: fanotify: Validate the return value of mnt_ns_from_dentry() before dereferencing The function do_fanotify_mark() does not validate if mnt_ns_from_dentry() returns NULL before dereferencing mntns->user_ns. This causes a NULL point…

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40045 - ASoC: codecs: wcd937x: set the comp soundwire port correctly

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: wcd937x: set the comp soundwire port correctly For some reason we endup with setting soundwire port for HPHL_COMP and HPHR_COMP as zero, this can potentially result in a memory corruption due to accessing and settin…

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40028 - binder: fix double-free in dbitmap

In the Linux kernel, the following vulnerability has been resolved: binder: fix double-free in dbitmap A process might fail to allocate a new bitmap when trying to expand its proc->dmap. In that case, dbitmap_grow() fails and frees the old bitmap via dbitmap_free(). However, the driver calls dbit…

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

7.0

CVSS3.1

CVE-2025-40044 - fs: udf: fix OOB read in lengthAllocDescs handling

In the Linux kernel, the following vulnerability has been resolved: fs: udf: fix OOB read in lengthAllocDescs handling When parsing Allocation Extent Descriptor, lengthAllocDescs comes from on-disk data and must be validated against the block size. Crafted or corrupted images may set lengthAllocD…

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

5.5

CVSS3.1

CVE-2025-40043 - net: nfc: nci: Add parameter validation for packet data

In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Add parameter validation for packet data Syzbot reported an uninitialized value bug in nci_init_req, which was introduced by commit 5aca7966d2a7 ("Merge tag 'perf-tools-fixes-for-v6.17-2025-09-16' of git://git.kern…

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.

7.0

CVSS3.1

CVE-2025-40034 - PCI/AER: Avoid NULL pointer dereference in aer_ratelimit()

In the Linux kernel, the following vulnerability has been resolved: PCI/AER: Avoid NULL pointer dereference in aer_ratelimit() When platform firmware supplies error information to the OS, e.g., via the ACPI APEI GHES mechanism, it may identify an error source device that doesn't advertise an AER …

📅 Published: Oct. 28, 2025, midnight 🔄 Last Modified: Oct. 30, 2025, 3:05 p.m.
Total resulsts: 316943
Page 99 of 31,695
« previous page » next page
Filters