CVE-2025-38585
- EPSS 0.02%
- Veröffentlicht 19.08.2025 17:15:35
- Zuletzt bearbeitet 26.11.2025 17:57:33
In the Linux kernel, the following vulnerability has been resolved: staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() When gmin_get_config_var() calls efi.get_variable() and the EFI variable is larger than the expected buffer...
- EPSS 0.06%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 03.11.2025 18:16:29
In the Linux kernel, the following vulnerability has been resolved: ipv6: reject malicious packets in ipv6_gso_segment() syzbot was able to craft a packet with very long IPv6 extension headers leading to an overflow of skb->transport_header. This ...
CVE-2025-38573
- EPSS 0.02%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 26.11.2025 19:59:58
In the Linux kernel, the following vulnerability has been resolved: spi: cs42l43: Property entry should be a null-terminated array The software node does not specify a count of property entries, so the array must be null-terminated. When untermina...
- EPSS 0.06%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 03.11.2025 18:16:29
In the Linux kernel, the following vulnerability has been resolved: pptp: ensure minimal skb length in pptp_xmit() Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data on ppp_sync_txmung") fixed ppp_sync_txmunge() We need a similar fix ...
- EPSS 0.06%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 03.11.2025 18:16:30
In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: Make EEH driver device hotplug safe Multiple race conditions existed between the PCIe hotplug driver and the EEH driver, leading to a variety of kernel oopses of the s...
- EPSS 0.06%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 03.11.2025 18:16:30
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid panic in f2fs_evict_inode As syzbot [1] reported as below: R10: 0000000000000100 R11: 0000000000000206 R12: 00007ffe17473450 R13: 00007f28b1c10854 R14: 00000000...
- EPSS 0.06%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 03.11.2025 18:16:30
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid UAF in f2fs_sync_inode_meta() syzbot reported an UAF issue as below: [1] [2] [1] https://syzkaller.appspot.com/text?tag=CrashReport&x=16594c60580000 ==========...
- EPSS 0.06%
- Veröffentlicht 19.08.2025 17:15:33
- Zuletzt bearbeitet 03.11.2025 18:16:29
In the Linux kernel, the following vulnerability has been resolved: perf/core: Exit early on perf_mmap() fail When perf_mmap() fails to allocate a buffer, it still invokes the event_mapped() callback of the related event. On X86 this might increase...
CVE-2025-38566
- EPSS 0.09%
- Veröffentlicht 19.08.2025 17:15:33
- Zuletzt bearbeitet 26.11.2025 18:15:05
In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit in NFS over TLS in tls_alert_recv() due to its assumption it can read data from the msg it...
CVE-2025-38567
- EPSS 0.02%
- Veröffentlicht 19.08.2025 17:15:33
- Zuletzt bearbeitet 26.11.2025 20:05:59
In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid ref leak in nfsd_open_local_fh() If two calls to nfsd_open_local_fh() race and both successfully call nfsd_file_acquire_local(), they will both get an extra reference t...