5.5

CVSS3.1

CVE-2026-22985 - idpf: Fix RSS LUT NULL pointer crash on early ethtool operations

In the Linux kernel, the following vulnerability has been resolved: idpf: Fix RSS LUT NULL pointer crash on early ethtool operations The RSS LUT is not initialized until the interface comes up, causing the following NULL pointer crash when ethtool operations like rxhash on/off are performed befor…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 6:48 p.m.

5.5

CVSS3.1

CVE-2026-22981 - idpf: detach and close netdevs while handling a reset

In the Linux kernel, the following vulnerability has been resolved: idpf: detach and close netdevs while handling a reset Protect the reset path from callbacks by setting the netdevs to detached state and close any netdevs in UP state until the reset handling has completed. During a reset, the dr…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 6:48 p.m.

7.8

CVSS3.1

CVE-2025-71159 - btrfs: fix use-after-free warning in btrfs_get_or_create_delayed_node()

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free warning in btrfs_get_or_create_delayed_node() Previously, btrfs_get_or_create_delayed_node() set the delayed_node's refcount before acquiring the root->delayed_nodes lock. Commit e8513c012de7 ("btrfs: im…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 8:19 p.m.

9.9

CVSS3.1

CVE-2025-70983 -

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:28 p.m.

7.8

CVSS3.1

CVE-2026-22995 - ublk: fix use-after-free in ublk_partition_scan_work

In the Linux kernel, the following vulnerability has been resolved: ublk: fix use-after-free in ublk_partition_scan_work A race condition exists between the async partition scan work and device teardown that can lead to a use-after-free of ub->ub_disk: 1. ublk_ctrl_start_dev() schedules partitio…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:13 p.m.

5.5

CVSS3.1

CVE-2026-22994 - bpf: Fix reference count leak in bpf_prog_test_run_xdp()

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reference count leak in bpf_prog_test_run_xdp() syzbot is reporting unregister_netdevice: waiting for sit0 to become free. Usage count = 2 problem. A debug printk() patch found that a refcount is obtained at xdp_conv…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 5:19 p.m.

5.5

CVSS3.1

CVE-2026-22989 - nfsd: check that server is running in unlock_filesystem

In the Linux kernel, the following vulnerability has been resolved: nfsd: check that server is running in unlock_filesystem If we are trying to unlock the filesystem via an administrative interface and nfsd isn't running, it crashes the server. This happens currently because nfsd4_revoke_states()…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 6:51 p.m.

5.5

CVSS3.1

CVE-2026-22988 - arp: do not assume dev_hard_header() does not change skb->head

In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not change skb->head arp_create() is the only dev_hard_header() caller making assumption about skb->head being unchanged. A recent commit broke this assumption. Initialize @arp pointer …

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 6:51 p.m.

4.7

CVSS3.1

CVE-2026-22986 - gpiolib: fix race condition for gdev->srcu

In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix race condition for gdev->srcu If two drivers were calling gpiochip_add_data_with_key(), one may be traversing the srcu-protected list in gpio_name_to_desc(), meanwhile other has just added its gdev in gpiodev_add_to_…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 26, 2026, 6:48 p.m.

5.3

CVSS3.1

CVE-2025-52022 -

A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when specially crafted HTTP GET/POST requests are sent to public…

πŸ“… Published: Jan. 23, 2026, midnight πŸ”„ Last Modified: Feb. 11, 2026, 7:25 p.m.
Total resulsts: 343921
Page 1463 of 34,393
Β« previous page Β» next page
Filters