CVE-2025-37893
- EPSS 0.06%
- Veröffentlicht 18.04.2025 07:01:28
- Zuletzt bearbeitet 01.10.2025 17:15:45
In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prologue() Vincent reported that running BPF progs with tailcalls on LoongArch causes kernel hard lockup. Debugging the issues shows t...
CVE-2025-37785
- EPSS 0.06%
- Veröffentlicht 18.04.2025 07:01:27
- Zuletzt bearbeitet 03.11.2025 20:18:34
In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bounds read (la...
CVE-2021-47671
- EPSS 0.05%
- Veröffentlicht 17.04.2025 18:01:31
- Zuletzt bearbeitet 21.04.2025 18:40:48
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling netif_rx(skb). ...
CVE-2021-47670
- EPSS 0.07%
- Veröffentlicht 17.04.2025 18:01:30
- Zuletzt bearbeitet 21.04.2025 18:41:16
In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after...
CVE-2021-47668
- EPSS 0.06%
- Veröffentlicht 17.04.2025 18:01:29
- Zuletzt bearbeitet 21.04.2025 18:41:27
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after t...
CVE-2021-47669
- EPSS 0.06%
- Veröffentlicht 17.04.2025 18:01:29
- Zuletzt bearbeitet 21.04.2025 18:41:22
In the Linux kernel, the following vulnerability has been resolved: can: vxcan: vxcan_xmit: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the canfd_frame cfd which aliases skb memory is accessed aft...
CVE-2020-36789
- EPSS 0.06%
- Veröffentlicht 17.04.2025 18:01:28
- Zuletzt bearbeitet 01.10.2025 17:15:31
In the Linux kernel, the following vulnerability has been resolved: can: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context If a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but not always, the case),...
CVE-2025-23137
- EPSS 0.08%
- Veröffentlicht 16.04.2025 14:13:17
- Zuletzt bearbeitet 27.06.2025 11:15:24
In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update Check if policy is NULL before dereferencing it in amd_pstate_update.
CVE-2025-23138
- EPSS 0.12%
- Veröffentlicht 16.04.2025 14:13:17
- Zuletzt bearbeitet 04.11.2025 17:00:09
In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currently, watch_queue_set_size() modifies the pipe buffers charged to user->pipe_bufs without updating the pipe->nr_accounted on the pipe...
CVE-2025-23136
- EPSS 0.1%
- Veröffentlicht 16.04.2025 14:13:16
- Zuletzt bearbeitet 03.11.2025 20:17:44
In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companion fwnode, so adev might be NULL. This is similar to the commit cd2fd6eab480 ("platform/x86: int3472: ...