CVE-2025-38176
- EPSS 0.01%
- Veröffentlicht 04.07.2025 10:39:57
- Zuletzt bearbeitet 19.11.2025 21:03:50
In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode() Running 'stress-ng --binderfs 16 --timeout 300' under KASAN-enabled kernel, I've noticed the following: BUG: KASAN: slab-use-a...
CVE-2025-38175
- EPSS 0.01%
- Veröffentlicht 04.07.2025 10:39:56
- Zuletzt bearbeitet 19.11.2025 21:04:54
In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Commit e77aff5528a18 ("binderfs: fix use-after-free in binder_devices") addressed a use-after-free where devices could be released wit...
CVE-2025-38174
- EPSS 0.03%
- Veröffentlicht 04.07.2025 10:39:55
- Zuletzt bearbeitet 18.12.2025 16:46:25
In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Do not double dequeue a configuration request Some of our devices crash in tb_cfg_request_dequeue(): general protection fault, probably for non-canonical address 0xd...
CVE-2025-38172
- EPSS 0.01%
- Veröffentlicht 03.07.2025 08:36:10
- Zuletzt bearbeitet 20.11.2025 19:22:42
In the Linux kernel, the following vulnerability has been resolved: erofs: avoid using multiple devices with different type For multiple devices, both primary and extra devices should be the same type. `erofs_init_device` has already guaranteed tha...
CVE-2025-38173
- EPSS 0.03%
- Veröffentlicht 03.07.2025 08:36:10
- Zuletzt bearbeitet 18.12.2025 20:53:34
In the Linux kernel, the following vulnerability has been resolved: crypto: marvell/cesa - Handle zero-length skcipher requests Do not access random memory for zero-length skcipher requests. Just return 0.
CVE-2025-38170
- EPSS 0.03%
- Veröffentlicht 03.07.2025 08:36:09
- Zuletzt bearbeitet 18.12.2025 20:53:13
In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Discard stale CPU state when handling SME traps The logic for handling SME traps manipulates saved FPSIMD/SVE/SME state incorrectly, and a race with preemption can re...
CVE-2025-38171
- EPSS 0.02%
- Veröffentlicht 03.07.2025 08:36:09
- Zuletzt bearbeitet 20.11.2025 19:24:31
In the Linux kernel, the following vulnerability has been resolved: power: supply: max77705: Fix workqueue error handling in probe The create_singlethread_workqueue() doesn't return error pointers, it returns NULL. Also cleanup the workqueue on th...
CVE-2025-38169
- EPSS 0.01%
- Veröffentlicht 03.07.2025 08:36:08
- Zuletzt bearbeitet 20.11.2025 19:28:15
In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: Avoid clobbering kernel FPSIMD state with SMSTOP On system with SME, a thread's kernel FPSIMD state may be erroneously clobbered during a context switch immediately a...
CVE-2025-38168
- EPSS 0.01%
- Veröffentlicht 03.07.2025 08:36:07
- Zuletzt bearbeitet 20.11.2025 19:29:30
In the Linux kernel, the following vulnerability has been resolved: perf: arm-ni: Unregister PMUs on probe failure When a resource allocation fails in one clock domain of an NI device, we need to properly roll back all previously registered perf PM...
CVE-2025-38166
- EPSS 0.04%
- Veröffentlicht 03.07.2025 08:36:06
- Zuletzt bearbeitet 18.12.2025 20:51:59
In the Linux kernel, the following vulnerability has been resolved: bpf: fix ktls panic with sockmap [ 2172.936997] ------------[ cut here ]------------ [ 2172.936999] kernel BUG at lib/iov_iter.c:629! ...... [ 2172.944996] PKRU: 55555554 [ 2172.94...