5.5

CVSS3.1

CVE-2025-21912 - gpio: rcar: Use raw_spinlock to protect register access

In the Linux kernel, the following vulnerability has been resolved: gpio: rcar: Use raw_spinlock to protect register access Use raw_spinlock in order to fix spurious messages about invalid context when spinlock debugging is enabled. The lock is only used to serialize register access. [ 4.…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Jan. 2, 2026, 3:28 p.m.

4.7

CVSS3.1

CVE-2025-21958 - Revert "openvswitch: switch to per-action label counting in conntrack"

In the Linux kernel, the following vulnerability has been resolved: Revert "openvswitch: switch to per-action label counting in conntrack" Currently, ovs_ct_set_labels() is only called for confirmed conntrack entries (ct) within ovs_ct_commit(). However, if the conntrack entry does not have the l…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 7:44 p.m.

5.5

CVSS3.1

CVE-2025-21894 - net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC

In the Linux kernel, the following vulnerability has been resolved: net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC Actually ENETC VFs do not support HWTSTAMP_TX_ONESTEP_SYNC because only ENETC PF can access PMa_SINGLE_STEP registers. And there will be a crash if VFs are used to test one-…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:50 p.m.

5.5

CVSS3.1

CVE-2025-21961 - eth: bnxt: fix truesize for mb-xdp-pass case

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix truesize for mb-xdp-pass case When mb-xdp is set and return is XDP_PASS, packet is converted from xdp_buff to sk_buff with xdp_update_skb_shared_info() in bnxt_xdp_build_skb(). bnxt_xdp_build_skb() passes incorrect…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 1, 2025, 6:15 p.m.

4.6

CVSS3.1

CVE-2025-28132 -

A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing a…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: June 18, 2025, 1:59 p.m.

5.5

CVSS3.1

CVE-2025-21922 - ppp: Fix KMSAN uninit-value warning with bpf

In the Linux kernel, the following vulnerability has been resolved: ppp: Fix KMSAN uninit-value warning with bpf Syzbot caught an "KMSAN: uninit-value" warning [1], which is caused by the ppp driver not initializing a 2-byte header when using socket filter. The following code can generate a PPP …

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:17 p.m.

7.1

CVSS3.1

CVE-2025-21985 - drm/amd/display: Fix out-of-bound accesses

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bound accesses [WHAT & HOW] hpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4), but location can have size up to 6. As a result, it is necessary to check location against MAX_HPO_DP2_…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 30, 2025, 7:17 p.m.

4.6

CVSS3.1

CVE-2025-28131 -

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling …

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: July 11, 2025, 1:39 p.m.

7.8

CVSS3.1

CVE-2025-21929 - HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove()

In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove() During the `rmmod` operation for the `intel_ishtp_hid` driver, a use-after-free issue can occur in the hid_ishtp_cl_remove() function. The function hid_ishtp_c…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: May 4, 2025, 7:24 a.m.

7.8

CVSS3.1

CVE-2025-21896 - fuse: revert back to __readahead_folio() for readahead

In the Linux kernel, the following vulnerability has been resolved: fuse: revert back to __readahead_folio() for readahead In commit 3eab9d7bc2f4 ("fuse: convert readahead to use folios"), the logic was converted to using the new folio readahead code, which drops the reference on the folio once i…

πŸ“… Published: April 1, 2025, midnight πŸ”„ Last Modified: Oct. 31, 2025, 6:50 p.m.
Total resulsts: 343168
Page 5493 of 34,317
Β« previous page Β» next page
Filters