7.0

CVSS3.1

CVE-2025-68312 - usbnet: Prevents free active kevent

In the Linux kernel, the following vulnerability has been resolved: usbnet: Prevents free active kevent The root cause of this issue are: 1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0); put the kevent work in global workqueue. However, the kevent has not yet been sched…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68207 - drm/xe/guc: Synchronize Dead CT worker with unbind

In the Linux kernel, the following vulnerability has been resolved: drm/xe/guc: Synchronize Dead CT worker with unbind Cancel and wait for any Dead CT worker to complete before continuing with device unbinding. Else the worker will end up using resources freed by the undind operation. (cherry pi…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68181 - drm/radeon: Remove calls to drm_put_dev()

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Remove calls to drm_put_dev() Since the allocation of the drivers main structure was changed to devm_drm_dev_alloc() drm_put_dev()'ing to trigger it to be free'd should be done by devres. However, drm_put_dev() is st…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68313 - x86/CPU/AMD: Add RDSEED fix for Zen5

In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Add RDSEED fix for Zen5 There's an issue with RDSEED's 16-bit and 32-bit register output variants on Zen5 which return a random value of 0 "at a rate inconsistent with randomness while incorrectly signaling success (…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:34 p.m.

7.0

CVSS3.1

CVE-2025-68301 - net: atlantic: fix fragment overflow handling in RX path

In the Linux kernel, the following vulnerability has been resolved: net: atlantic: fix fragment overflow handling in RX path The atlantic driver can receive packets with more than MAX_SKB_FRAGS (17) fragments when handling large multi-descriptor packets. This causes an out-of-bounds write in skb_…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68212 - fs: Fix uninitialized 'offp' in statmount_string()

In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized 'offp' in statmount_string() In statmount_string(), most flags assign an output offset pointer (offp) which is later updated with the string offset. However, the STATMOUNT_MNT_UIDMAP and STATMOUNT_MNT_GIDMAP…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Jan. 17, 2026, 3:46 p.m.

0.0

CVE-2025-68216 - LoongArch: BPF: Disable trampoline for kernel module function trace

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Disable trampoline for kernel module function trace The current LoongArch BPF trampoline implementation is incompatible with tracing functions in kernel modules. This causes several severe and user-visible problem…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.3

CVSS3.1

CVE-2025-65581 -

An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Jan. 7, 2026, 9 p.m.

9.1

CVSS3.1

CVE-2025-65318 -

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS and third-party software.

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 31, 2025, 12:38 a.m.

7.0

CVSS3.1

CVE-2025-40348 - slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts

In the Linux kernel, the following vulnerability has been resolved: slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts If two competing threads enter alloc_slab_obj_exts() and one of them fails to allocate the object extension vector, it might override the valid slab->obj_exts allocated by…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.
Total resulsts: 343947
Page 2061 of 34,395
Β« previous page Β» next page
Filters