CVE-2025-21998
- EPSS 0.04%
- Veröffentlicht 03.04.2025 08:15:15
- Zuletzt bearbeitet 01.10.2025 18:15:42
In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: fix efivars registration race Since the conversion to using the TZ allocator, the efivars service is registered before the memory pool has been allocate...
CVE-2025-21999
- EPSS 0.05%
- Veröffentlicht 03.04.2025 08:15:15
- Zuletzt bearbeitet 03.11.2025 20:17:36
In the Linux kernel, the following vulnerability has been resolved: proc: fix UAF in proc_get_inode() Fix race between rmmod and /proc/XXX's inode instantiation. The bug is that pde->proc_ops don't belong to /proc, it belongs to a module, therefor...
CVE-2025-22000
- EPSS 0.05%
- Veröffentlicht 03.04.2025 08:15:15
- Zuletzt bearbeitet 01.10.2025 18:15:42
In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: drop beyond-EOF folios with the right number of refs When an after-split folio is large and needs to be dropped due to EOF, folio_put_refs(folio, folio_nr_pages(fol...
CVE-2025-22001
- EPSS 0.07%
- Veröffentlicht 03.04.2025 08:15:15
- Zuletzt bearbeitet 01.10.2025 17:15:40
In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix integer overflow in qaic_validate_req() These are u64 variables that come from the user via qaic_attach_slice_bo_ioctl(). Use check_add_overflow() to ensure that t...
CVE-2025-22002
- EPSS 0.05%
- Veröffentlicht 03.04.2025 08:15:15
- Zuletzt bearbeitet 01.10.2025 17:15:40
In the Linux kernel, the following vulnerability has been resolved: netfs: Call `invalidate_cache` only if implemented Many filesystems such as NFS and Ceph do not implement the `invalidate_cache` method. On those filesystems, if writing to the ca...
CVE-2025-22003
- EPSS 0.06%
- Veröffentlicht 03.04.2025 08:15:15
- Zuletzt bearbeitet 01.10.2025 17:15:41
In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix out of bound read in strscpy() source Commit 7fdaf8966aae ("can: ucan: use strscpy() to instead of strncpy()") unintentionally introduced a one byte out of bound rea...
CVE-2025-22004
- EPSS 0.05%
- Veröffentlicht 03.04.2025 08:15:15
- Zuletzt bearbeitet 03.11.2025 20:17:36
In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->send() operation frees skb so save the length before calling ->send() to avoid a use after free.
CVE-2025-21995
- EPSS 0.07%
- Veröffentlicht 03.04.2025 08:15:14
- Zuletzt bearbeitet 01.10.2025 19:15:34
In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix fence reference count leak The last_scheduled fence leaks when an entity is being killed and adding the cleanup callback fails. Decrement the reference count of pre...
CVE-2025-21994
- EPSS 0.09%
- Veröffentlicht 02.04.2025 14:16:01
- Zuletzt bearbeitet 03.11.2025 20:17:35
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field of smb_acl parse_dcal() validate num_aces to allocate posix_ace_state_array. if (num_aces > ULONG_MAX / sizeof(struct smb_ace *)...
CVE-2025-21987
- EPSS 0.05%
- Veröffentlicht 02.04.2025 13:15:43
- Zuletzt bearbeitet 30.10.2025 19:20:31
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: init return value in amdgpu_ttm_clear_buffer Otherwise an uninitialized value can be returned if amdgpu_res_cleared returns true for all regions. Possibly closes: http...