CVE-2025-38712
- EPSS 0.02%
- Veröffentlicht 04.09.2025 15:33:02
- Zuletzt bearbeitet 12.05.2026 13:17:01
In the Linux kernel, the following vulnerability has been resolved: hfsplus: don't use BUG_ON() in hfsplus_create_attributes_file() When the volume header contains erroneous values that do not reflect the actual state of the filesystem, hfsplus_fil...
CVE-2025-38710
- EPSS 0.01%
- Veröffentlicht 04.09.2025 15:33:00
- Zuletzt bearbeitet 11.04.2026 13:16:35
In the Linux kernel, the following vulnerability has been resolved: gfs2: Validate i_depth for exhash directories A fuzzer test introduced corruption that ends up with a depth of 0 in dir_e_read(), causing an undefined shift by 32 at: index = ha...
CVE-2025-38708
- EPSS 0.02%
- Veröffentlicht 04.09.2025 15:32:59
- Zuletzt bearbeitet 12.05.2026 13:17:01
In the Linux kernel, the following vulnerability has been resolved: drbd: add missing kref_get in handle_write_conflicts With `two-primaries` enabled, DRBD tries to detect "concurrent" writes and handle write conflicts, so that even if you write to...
CVE-2025-38709
- EPSS 0.03%
- Veröffentlicht 04.09.2025 15:32:59
- Zuletzt bearbeitet 03.12.2025 20:00:20
In the Linux kernel, the following vulnerability has been resolved: loop: Avoid updating block size under exclusive owner Syzbot came up with a reproducer where a loop device block size is changed underneath a mounted filesystem. This causes a mism...
CVE-2025-38706
- EPSS 0.02%
- Veröffentlicht 04.09.2025 15:32:57
- Zuletzt bearbeitet 12.05.2026 13:17:00
In the Linux kernel, the following vulnerability has been resolved: ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() snd_soc_remove_pcm_runtime() might be called with rtd == NULL which will leads to null pointer dereference. This w...
CVE-2025-38705
- EPSS 0.01%
- Veröffentlicht 04.09.2025 15:32:56
- Zuletzt bearbeitet 24.11.2025 19:43:18
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix null pointer access Writing a string without delimiters (' ', '\n', '\0') to the under gpu_od/fan_ctrl sysfs or pp_power_profile_mode for the CUSTOM profile will re...
CVE-2025-38701
- EPSS 0.01%
- Veröffentlicht 04.09.2025 15:32:53
- Zuletzt bearbeitet 12.05.2026 13:16:59
In the Linux kernel, the following vulnerability has been resolved: ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr A syzbot fuzzed image triggered a BUG_ON in ext4_update_inline_data() when an inode had the INLINE_DATA_FL flag set but...
CVE-2025-38702
- EPSS 0.01%
- Veröffentlicht 04.09.2025 15:32:53
- Zuletzt bearbeitet 12.05.2026 13:17:00
In the Linux kernel, the following vulnerability has been resolved: fbdev: fix potential buffer overflow in do_register_framebuffer() The current implementation may lead to buffer overflow when: 1. Unregistration creates NULL gaps in registered_fb...
CVE-2025-38700
- EPSS 0.02%
- Veröffentlicht 04.09.2025 15:32:52
- Zuletzt bearbeitet 12.05.2026 13:16:59
In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated In case of an ib_fast_reg_mr allocation failure during iSER setup, the machine hits a panic because iscsi...
CVE-2025-38699
- EPSS 0.02%
- Veröffentlicht 04.09.2025 15:32:51
- Zuletzt bearbeitet 12.05.2026 13:16:59
In the Linux kernel, the following vulnerability has been resolved: scsi: bfa: Double-free fix When the bfad_im_probe() function fails during initialization, the memory pointed to by bfad->im is freed without setting bfad->im to NULL. Subsequently...