CVE-2025-38555
- EPSS 0.02%
- Veröffentlicht 19.08.2025 17:15:31
- Zuletzt bearbeitet 08.01.2026 20:49:46
In the Linux kernel, the following vulnerability has been resolved: usb: gadget : fix use-after-free in composite_dev_cleanup() 1. In func configfs_composite_bind() -> composite_os_desc_req_prepare(): if kmalloc fails, the pointer cdev->os_desc_req...
CVE-2025-38556
- EPSS 0.02%
- Veröffentlicht 19.08.2025 17:15:31
- Zuletzt bearbeitet 19.01.2026 13:16:08
In the Linux kernel, the following vulnerability has been resolved: HID: core: Harden s32ton() against conversion to 0 bits Testing by the syzbot fuzzer showed that the HID core gets a shift-out-of-bounds exception when it tries to convert a 32-bit...
CVE-2025-38553
- EPSS 0.02%
- Veröffentlicht 19.08.2025 06:15:33
- Zuletzt bearbeitet 08.01.2026 20:49:12
In the Linux kernel, the following vulnerability has been resolved: net/sched: Restrict conditions for adding duplicating netems to qdisc tree netem_enqueue's duplication prevention logic breaks when a netem resides in a qdisc tree with other netem...
CVE-2025-38548
- EPSS 0.03%
- Veröffentlicht 16.08.2025 11:34:16
- Zuletzt bearbeitet 07.01.2026 18:33:13
In the Linux kernel, the following vulnerability has been resolved: hwmon: (corsair-cpro) Validate the size of the received input buffer Add buffer_recv_size to store the size of the received bytes. Validate buffer_recv_size in send_usb_cmd().
CVE-2025-38546
- EPSS 0.02%
- Veröffentlicht 16.08.2025 11:22:20
- Zuletzt bearbeitet 07.01.2026 18:33:27
In the Linux kernel, the following vulnerability has been resolved: atm: clip: Fix memory leak of struct clip_vcc. ioctl(ATMARP_MKIP) allocates struct clip_vcc and set it to vcc->user_back. The code assumes that vcc_destroy_socket() passes NULL sk...
CVE-2025-38544
- EPSS 0.02%
- Veröffentlicht 16.08.2025 11:22:18
- Zuletzt bearbeitet 18.11.2025 18:09:45
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix bug due to prealloc collision When userspace is using AF_RXRPC to provide a server, it has to preallocate incoming calls and assign to them call IDs that will be used to...
CVE-2025-38542
- EPSS 0.02%
- Veröffentlicht 16.08.2025 11:22:16
- Zuletzt bearbeitet 07.01.2026 18:40:39
In the Linux kernel, the following vulnerability has been resolved: net: appletalk: Fix device refcount leak in atrtr_create() When updating an existing route entry in atrtr_create(), the old device reference was not being released before assigning...
CVE-2025-38540
- EPSS 0.03%
- Veröffentlicht 16.08.2025 11:22:14
- Zuletzt bearbeitet 22.01.2026 18:39:18
In the Linux kernel, the following vulnerability has been resolved: HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras The Chicony Electronics HP 5MP Cameras (USB ID 04F2:B824 & 04F2:B82C) report a HID sensor interface that is not actu...
CVE-2025-38539
- EPSS 0.03%
- Veröffentlicht 16.08.2025 11:12:31
- Zuletzt bearbeitet 07.01.2026 18:42:03
In the Linux kernel, the following vulnerability has been resolved: tracing: Add down_write(trace_event_sem) when adding trace event When a module is loaded, it adds trace events defined by the module. It may also need to modify the modules trace p...
CVE-2025-38538
- EPSS 0.03%
- Veröffentlicht 16.08.2025 11:12:30
- Zuletzt bearbeitet 07.01.2026 18:42:22
In the Linux kernel, the following vulnerability has been resolved: dmaengine: nbpfaxi: Fix memory corruption in probe() The nbpf->chan[] array is allocated earlier in the nbpf_probe() function and it has "num_channels" elements. These three loops...