5.5

CVSS3.1

CVE-2025-37958 - mm/huge_memory: fix dereferencing invalid pmd migration entry

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix dereferencing invalid pmd migration entry When migrating a THP, concurrent access to the PMD migration entry during a deferred split scan can lead to an invalid address access, as illustrated below. To preven…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 16, 2025, 8:37 p.m.

6.5

CVSS3.1

CVE-2025-45862 -

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s interface.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: May 24, 2025, 12:53 a.m.

7.1

CVSS3.1

CVE-2025-37975 - riscv: module: Fix out-of-bounds relocation access

In the Linux kernel, the following vulnerability has been resolved: riscv: module: Fix out-of-bounds relocation access The current code allows rel[j] to access one element past the end of the relocation section. Simplify to num_relocations which is equivalent to the existing size expression.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:01 p.m.

7.8

CVSS3.1

CVE-2025-37957 - KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception Previously, commit ed129ec9057f ("KVM: x86: forcibly leave nested mode on vCPU reset") addressed an issue where a triple fault occurring in nested mode could lead to use-…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:03 p.m.

7.8

CVSS3.1

CVE-2025-37916 - pds_core: remove write-after-free of client_id

In the Linux kernel, the following vulnerability has been resolved: pds_core: remove write-after-free of client_id A use-after-free error popped up in stress testing: [Mon Apr 21 21:21:33 2025] BUG: KFENCE: use-after-free write in pdsc_auxbus_dev_del+0xef/0x160 [pds_core] [Mon Apr 21 21:21:33 20…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 5:03 p.m.

9.8

CVSS3.1

CVE-2025-44884 -

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 3:54 p.m.

5.5

CVSS3.1

CVE-2025-37939 - libbpf: Fix accessing BTF.ext core_relo header

In the Linux kernel, the following vulnerability has been resolved: libbpf: Fix accessing BTF.ext core_relo header Update btf_ext_parse_info() to ensure the core_relo header is present before reading its fields. This avoids a potential buffer read overflow reported by the OSS Fuzz project.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 2:57 p.m.

7.5

CVSS3.1

CVE-2025-26086 -

An unauthenticated blind SQL injection vulnerability exists in RSI Queue Management System v3.0 within the TaskID parameter of the get request handler. Attackers can remotely inject time-delayed SQL payloads to induce server response delays, enabling time-based inference and iterative extraction of…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: June 12, 2025, 4:20 p.m.

5.5

CVSS3.1

CVE-2025-37953 - sch_htb: make htb_deactivate() idempotent

In the Linux kernel, the following vulnerability has been resolved: sch_htb: make htb_deactivate() idempotent Alan reported a NULL pointer dereference in htb_next_rb_node() after we made htb_qlen_notify() idempotent. It turns out in the following case it introduced some regression: htb_dequeue_…

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:04 p.m.

9.8

CVSS3.1

CVE-2025-44887 -

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

πŸ“… Published: May 20, 2025, midnight πŸ”„ Last Modified: May 29, 2025, 3:54 p.m.
Total resulsts: 344716
Page 4878 of 34,472
Β« previous page Β» next page
Filters