CVE-2025-23144
- EPSS 0.12%
- Veröffentlicht 01.05.2025 12:55:33
- Zuletzt bearbeitet 06.11.2025 17:39:57
In the Linux kernel, the following vulnerability has been resolved: backlight: led_bl: Hold led_access lock when calling led_sysfs_disable() Lockdep detects the following issue on led-backlight removal: [ 142.315935] ------------[ cut here ]----...
CVE-2025-23142
- EPSS 0.07%
- Veröffentlicht 01.05.2025 12:55:32
- Zuletzt bearbeitet 05.11.2025 22:04:01
In the Linux kernel, the following vulnerability has been resolved: sctp: detect and prevent references to a freed transport in sendmsg sctp_sendmsg() re-uses associations and transports when possible by doing a lookup based on the socket endpoint ...
CVE-2025-23141
- EPSS 0.04%
- Veröffentlicht 01.05.2025 12:55:31
- Zuletzt bearbeitet 05.11.2025 21:50:50
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses Acquire a lock on kvm->srcu when userspace is getting MP state to handle a rather extreme edge case wher...
CVE-2025-23140
- EPSS 0.07%
- Veröffentlicht 01.05.2025 12:55:30
- Zuletzt bearbeitet 05.11.2025 21:46:13
In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error After devm_request_irq() fails with error in pci_endpoint_test_request_irq(), the pci_endpoint_...
CVE-2025-3891
- EPSS 1.33%
- Veröffentlicht 29.04.2025 11:56:50
- Zuletzt bearbeitet 28.07.2025 14:15:27
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes c...
CVE-2025-21605
- EPSS 1.55%
- Veröffentlicht 23.04.2025 15:38:11
- Zuletzt bearbeitet 10.02.2026 18:16:13
Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can cause unlimited growth of output buffers, until the server runs out of memory or is killed. By default, t...
CVE-2025-43965
- EPSS 0.36%
- Veröffentlicht 23.04.2025 00:00:00
- Zuletzt bearbeitet 31.12.2025 15:41:59
In MIFF image processing in ImageMagick before 7.1.1-44, image depth is mishandled after SetQuantumFormat is used.
CVE-2025-38637
- EPSS 0.1%
- Veröffentlicht 18.04.2025 07:01:34
- Zuletzt bearbeitet 06.11.2025 21:35:04
In the Linux kernel, the following vulnerability has been resolved: net_sched: skbprio: Remove overly strict queue assertions In the current implementation, skbprio enqueue/dequeue contains an assertion that fails under certain conditions when SKBP...
CVE-2025-38575
- EPSS 0.13%
- Veröffentlicht 18.04.2025 07:01:33
- Zuletzt bearbeitet 17.03.2026 14:31:53
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use aead_request_free to match aead_request_alloc Use aead_request_free() instead of kfree() to properly free memory allocated by aead_request_alloc(). This ensures sensitiv...
- EPSS 47.07%
- Veröffentlicht 16.04.2025 21:34:37
- Zuletzt bearbeitet 04.11.2025 14:49:05
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in S...