7.0

CVSS3.1

CVE-2025-68304 - Bluetooth: hci_core: lookup hci_conn on RX path on protocol side

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: lookup hci_conn on RX path on protocol side The hdev lock/lookup/unlock/use pattern in the packet RX path doesn't ensure hci_conn* is not concurrently modified/deleted. This locking appears to be leftover fro…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-40360 - drm/sysfb: Do not dereference NULL pointer in plane reset

In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: Do not dereference NULL pointer in plane reset The plane state in __drm_gem_reset_shadow_plane() can be NULL. Do not deref that pointer, but forward NULL to the other plane-reset helpers. Clears plane->state to NULL. …

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

9.8

CVSS3.1

CVE-2025-62863 -

Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.5.1 allow an incorrectly formed SMC call to UEFI-MM PCIe driver that could result in an out-of-bounds write within PCIe driver’s S-EL0 address space.

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Jan. 13, 2026, 8:57 p.m.

0.0

CVE-2025-68210 - erofs: avoid infinite loop due to incomplete zstd-compressed data

In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loop due to incomplete zstd-compressed data Currently, the decompression logic incorrectly spins if compressed data is truncated in crafted (deliberately corrupted) images.

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

5.5

CVSS3.1

CVE-2025-68296 - drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup

In the Linux kernel, the following vulnerability has been resolved: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup Protect vga_switcheroo_client_fb_set() with console lock. Avoids OOB access in fbcon_remap_all(). Without holding the console lock the call races with switching outp…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

9.8

CVSS3.1

CVE-2025-68263 - ksmbd: ipc: fix use-after-free in ipc_msg_send_request

In the Linux kernel, the following vulnerability has been resolved: ksmbd: ipc: fix use-after-free in ipc_msg_send_request ipc_msg_send_request() waits for a generic netlink reply using an ipc_msg_table_entry on the stack. The generic netlink handler (handle_generic_event()/handle_response()) fil…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: April 2, 2026, 9:16 a.m.

5.5

CVSS3.1

CVE-2025-68219 - cifs: fix memory leak in smb3_fs_context_parse_param error path

In the Linux kernel, the following vulnerability has been resolved: cifs: fix memory leak in smb3_fs_context_parse_param error path Add proper cleanup of ctx->source and fc->source to the cifs_parse_mount_err error handler. This ensures that memory allocated for the source strings is correctly fr…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.0

CVSS3.1

CVE-2025-68243 - NFS: Check the TLS certificate fields in nfs_match_client()

In the Linux kernel, the following vulnerability has been resolved: NFS: Check the TLS certificate fields in nfs_match_client() If the TLS security policy is of type RPC_XPRTSEC_TLS_X509, then the cert_serial and privkey_serial fields need to match as well since they define the client's identity,…

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

0.0

CVE-2025-68235 - nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot

In the Linux kernel, the following vulnerability has been resolved: nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot nvkm_falcon_fw::boot is allocated, but no one frees it. This causes a kmemleak warning. Make sure this data is deallocated.

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Dec. 18, 2025, 3:08 p.m.

7.5

CVSS3.1

CVE-2025-52196 -

Server-Side Request Forgery (SSRF) vulnerability in Ctera Portal 8.1.x (8.1.1417.24) allows remote attackers to induce the server to make arbitrary HTTP requests via a crafted HTML file containing an iframe.

πŸ“… Published: Dec. 16, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 2:38 p.m.
Total resulsts: 343975
Page 2068 of 34,398
Β« previous page Β» next page
Filters