CVE-2025-22038
- EPSS 0.01%
- Veröffentlicht 16.04.2025 14:11:56
- Zuletzt bearbeitet 03.11.2025 20:17:38
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is accessed Access psid->sub_auth[psid->num_subauth - 1] without checking if num_subauth is non-zero leads to an out-of-bounds read...
CVE-2025-22039
- EPSS 0.01%
- Veröffentlicht 16.04.2025 14:11:56
- Zuletzt bearbeitet 14.11.2025 16:51:45
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing boun...
CVE-2025-22037
- EPSS 0.04%
- Veröffentlicht 16.04.2025 14:11:55
- Zuletzt bearbeitet 19.09.2025 15:15:48
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 se...
- EPSS 0.01%
- Veröffentlicht 16.04.2025 14:11:54
- Zuletzt bearbeitet 01.10.2025 17:15:43
In the Linux kernel, the following vulnerability has been resolved: exfat: fix random stack corruption after get_block When get_block is called with a buffer_head allocated on the stack, such as do_mpage_readpage, stack corruption due to buffer_hea...
CVE-2025-22034
- EPSS 0.02%
- Veröffentlicht 16.04.2025 14:11:53
- Zuletzt bearbeitet 31.10.2025 20:07:06
In the Linux kernel, the following vulnerability has been resolved: mm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs Patch series "mm: fixes for device-exclusive entries (hmm)", v2. Discussing the PageTail() call in make_device_exclusive_range() wi...
CVE-2025-22035
- EPSS 0.02%
- Veröffentlicht 16.04.2025 14:11:53
- Zuletzt bearbeitet 03.11.2025 20:17:38
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in print_graph_function_flags during tracer switching Kairui reported a UAF issue in print_graph_function_flags() during ftrace stress testing [1]. This...
CVE-2025-22032
- EPSS 0.02%
- Veröffentlicht 16.04.2025 14:11:52
- Zuletzt bearbeitet 01.10.2025 17:15:43
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix kernel panic due to null pointer dereference Address a kernel panic caused by a null pointer dereference in the `mt792x_rx_get_wcid` function. The issue ari...
CVE-2025-22033
- EPSS 0.03%
- Veröffentlicht 16.04.2025 14:11:52
- Zuletzt bearbeitet 03.11.2025 20:17:38
In the Linux kernel, the following vulnerability has been resolved: arm64: Don't call NULL in do_compat_alignment_fixup() do_alignment_t32_to_handler() only fixes up alignment faults for specific instructions; it returns NULL otherwise (e.g. LDREX)...
CVE-2025-22031
- EPSS 0.02%
- Veröffentlicht 16.04.2025 14:11:51
- Zuletzt bearbeitet 01.10.2025 17:15:43
In the Linux kernel, the following vulnerability has been resolved: PCI/bwctrl: Fix NULL pointer dereference on bus number exhaustion When BIOS neglects to assign bus numbers to PCI bridges, the kernel attempts to correct that during PCI device enu...
CVE-2025-22030
- EPSS 0.01%
- Veröffentlicht 16.04.2025 14:11:50
- Zuletzt bearbeitet 28.10.2025 19:05:41
In the Linux kernel, the following vulnerability has been resolved: mm: zswap: fix crypto_free_acomp() deadlock in zswap_cpu_comp_dead() Currently, zswap_cpu_comp_dead() calls crypto_free_acomp() while holding the per-CPU acomp_ctx mutex. crypto_f...