CVE-2025-38090
- EPSS 0.12%
- Veröffentlicht 30.06.2025 07:29:45
- Zuletzt bearbeitet 17.12.2025 18:13:28
In the Linux kernel, the following vulnerability has been resolved: drivers/rapidio/rio_cm.c: prevent possible heap overwrite In riocm_cdev_ioctl(RIO_CM_CHAN_SEND) -> cm_chan_msg_send() -> riocm_ch_send() cm_chan_msg_send() checks that u...
CVE-2025-38088
- EPSS 0.07%
- Veröffentlicht 30.06.2025 07:29:44
- Zuletzt bearbeitet 17.12.2025 18:13:20
In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap memtrace mmap issue has an out of bounds issue. This patch fixes the by checking that the requested mapping regio...
CVE-2025-32463
- EPSS 57.35%
- Veröffentlicht 30.06.2025 00:00:00
- Zuletzt bearbeitet 05.11.2025 19:26:48
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
CVE-2025-38086
- EPSS 0.11%
- Veröffentlicht 28.06.2025 07:52:58
- Zuletzt bearbeitet 17.12.2025 16:36:11
In the Linux kernel, the following vulnerability has been resolved: net: ch9200: fix uninitialised access during mii_nway_restart In mii_nway_restart() the code attempts to call mii->mdio_read which is ch9200_mdio_read(). ch9200_mdio_read() utilise...
CVE-2025-38085
- EPSS 0.09%
- Veröffentlicht 28.06.2025 07:44:26
- Zuletzt bearbeitet 18.12.2025 21:21:33
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race huge_pmd_unshare() drops a reference on a page table that may have previously been shared across processes, potentially turning ...
CVE-2025-38084
- EPSS 0.09%
- Veröffentlicht 28.06.2025 07:44:25
- Zuletzt bearbeitet 18.12.2025 21:20:39
In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: unshare page tables during VMA split, not before Currently, __split_vma() triggers hugetlb page table unsharing through vm_ops->may_split(). This happens before the VM...
CVE-2014-7210
- EPSS 0.35%
- Veröffentlicht 26.06.2025 20:52:47
- Zuletzt bearbeitet 06.08.2025 16:38:04
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affec...
CVE-2025-38083
- EPSS 0.09%
- Veröffentlicht 20.06.2025 11:21:51
- Zuletzt bearbeitet 12.05.2026 13:16:42
In the Linux kernel, the following vulnerability has been resolved: net_sched: prio: fix a race in prio_tune() Gerrard Tai reported a race condition in PRIO, whenever SFQ perturb timer fires at the wrong time. The race is as follows: CPU 0 ...
CVE-2025-38079
- EPSS 0.08%
- Veröffentlicht 18.06.2025 09:33:53
- Zuletzt bearbeitet 12.05.2026 13:16:42
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on socket type algif_hash with MSG_MORE flag set and crypto_ahash_import fails, sk2 is freed. However, it...
CVE-2025-38078
- EPSS 0.07%
- Veröffentlicht 18.06.2025 09:33:52
- Zuletzt bearbeitet 17.12.2025 17:57:43
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix race of buffer access at PCM OSS layer The PCM OSS layer tries to clear the buffer with the silence data at initialization (or reconfiguration) of a stream with the ...