0.0

CVE-2025-38224 - can: kvaser_pciefd: refine error prone echo_skb_max handling logic

In the Linux kernel, the following vulnerability has been resolved: can: kvaser_pciefd: refine error prone echo_skb_max handling logic echo_skb_max should define the supported upper limit of echo_skb[] allocated inside the netdevice's priv. The corresponding size value provided by this driver to …

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

0.0

CVE-2025-38218 - f2fs: fix to do sanity check on sit_bitmap_size

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on sit_bitmap_size w/ below testcase, resize will generate a corrupted image which contains inconsistent metadata, so when mounting such image, it will trigger kernel panic: touch img truncate -s $((…

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

0.0

CVE-2025-38216 - iommu/vt-d: Restore context entry setup order for aliased devices

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Restore context entry setup order for aliased devices Commit 2031c469f816 ("iommu/vt-d: Add support for static identity domain") changed the context entry setup during domain attachment from a set-and-check policy to …

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

0.0

CVE-2025-38214 - fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var

In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_set_var to prevent null-ptr-deref in fb_videomode_to_var If fb_add_videomode() in fb_set_var() fails to allocate memory for fb_videomode, later it may lead to a null-ptr dereference in fb_videomode_to_var(), as the …

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

0.0

CVE-2025-38212 - ipc: fix to protect IPCS lookups using RCU

In the Linux kernel, the following vulnerability has been resolved: ipc: fix to protect IPCS lookups using RCU syzbot reported that it discovered a use-after-free vulnerability, [0] [0]: https://lore.kernel.org/all/[email protected]/ idr_for_each() is protected by rwse…

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

0.0

CVE-2025-38211 - RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction

In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction The commit 59c68ac31e15 ("iw_cm: free cm_id resources on the last deref") simplified cm_id resource management by freeing cm_id once all references to the cm_i…

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

0.0

CVE-2025-38209 - nvme-tcp: remove tag set when second admin queue config fails

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue config fails Commit 104d0e2f6222 ("nvme-fabrics: reset admin connection for secure concatenation") modified nvme_tcp_setup_ctrl() to call nvme_tcp_configure_admin_queue() twice. Th…

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

0.0

CVE-2025-38203 - jfs: Fix null-ptr-deref in jfs_ioc_trim

In the Linux kernel, the following vulnerability has been resolved: jfs: Fix null-ptr-deref in jfs_ioc_trim [ Syzkaller Report ] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000087: 0000 [#1 KASAN: null-ptr-deref in range [0x0000000000000438-0x000000000000043f] …

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 7, 2025, 8:46 a.m.

0.0

CVE-2025-38200 - i40e: fix MMIO write access to an invalid page in i40e_clear_hw

In the Linux kernel, the following vulnerability has been resolved: i40e: fix MMIO write access to an invalid page in i40e_clear_hw When the device sends a specific input, an integer underflow can occur, leading to MMIO write access to an invalid page. Prevent the integer underflow by changing t…

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.

0.0

CVE-2025-38198 - fbcon: Make sure modelist not set on unregistered console

In the Linux kernel, the following vulnerability has been resolved: fbcon: Make sure modelist not set on unregistered console It looks like attempting to write to the "store_modes" sysfs node will run afoul of unregistered consoles: UBSAN: array-index-out-of-bounds in drivers/video/fbdev/core/fb…

πŸ“… Published: July 4, 2025, 1:37 p.m. πŸ”„ Last Modified: July 4, 2025, 2:15 p.m.
Total resulsts: 300619
Page 13 of 30,062
Β« previous page Β» next page
Filters