CVE-2025-40284
- EPSS 0.14%
- Veröffentlicht 06.12.2025 21:51:08
- Zuletzt bearbeitet 30.07.2026 06:24:26
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: cancel mesh send timer when hdev removed mesh_send_done timer is not canceled when hdev is removed, which causes crash if the timer triggers after hdev is gone. C...
CVE-2025-40282
- EPSS 0.27%
- Veröffentlicht 06.12.2025 21:51:06
- Zuletzt bearbeitet 30.07.2026 06:24:26
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: 6lowpan: reset link-local header on ipv6 recv path Bluetooth 6lowpan.c netdev has header_ops, so it must set link-local header for RX skb, otherwise things crash, eg. wi...
CVE-2025-40271
- EPSS 0.45%
- Veröffentlicht 06.12.2025 21:50:53
- Zuletzt bearbeitet 30.07.2026 06:24:24
In the Linux kernel, the following vulnerability has been resolved: fs/proc: fix uaf in proc_readdir_de() Pde is erased from subdir rbtree through rb_erase(), but not set the node to EMPTY, which may result in uaf access. We should use RB_CLEAR_NO...
CVE-2025-40269
- EPSS 0.17%
- Veröffentlicht 06.12.2025 21:50:50
- Zuletzt bearbeitet 30.07.2026 06:24:24
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential overflow of PCM transfer buffer The PCM stream data in USB-audio driver is transferred over USB URB packet buffers, and each packet size is determine...
- EPSS 0.18%
- Veröffentlicht 06.12.2025 21:50:48
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: cifs: client: fix memory leak in smb3_fs_context_parse_param The user calls fsconfig twice, but when the program exits, free() only frees ctx->source for the second fsconfig, not t...
- EPSS 0.19%
- Veröffentlicht 04.12.2025 16:16:20
- Zuletzt bearbeitet 02.06.2026 14:16:32
In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`) in cros_ec_keyb_probe(), `ckdev->idev` remains NU...
CVE-2025-40266
- EPSS 0.15%
- Veröffentlicht 04.12.2025 16:16:20
- Zuletzt bearbeitet 30.07.2026 06:24:23
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Check the untrusted offset in FF-A memory share Verify the offset to prevent OOB access in the hypervisor FF-A buffer in case an untrusted large enough value [U32_MAX -...
- EPSS 0.18%
- Veröffentlicht 04.12.2025 16:16:18
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix pgtable prealloc error path The following splat was reported: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010 Mem abort i...
CVE-2025-40248
- EPSS 0.15%
- Veröffentlicht 04.12.2025 16:16:18
- Zuletzt bearbeitet 30.07.2026 06:24:21
In the Linux kernel, the following vulnerability has been resolved: vsock: Ignore signal/timeout on connect() if already established During connect(), acting on a signal/timeout by disconnecting an already established socket leads to several issues...
CVE-2025-40250
- EPSS 0.15%
- Veröffentlicht 04.12.2025 16:16:18
- Zuletzt bearbeitet 30.07.2026 06:24:22
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq() failure The mlx5_irq_alloc() function can inadvertently free the entire rmap and end up in a crash[1] when the other threads t...