- EPSS 0.19%
- Veröffentlicht 29.10.2025 13:37:01
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix null-deref in agg_dequeue To prevent a potential crash in agg_dequeue (net/sched/sch_qfq.c) when cl->qdisc->ops->peek(cl->qdisc) returns NULL, we check the ...
- EPSS 0.17%
- Veröffentlicht 28.10.2025 11:48:40
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: drm/msm: Do not validate SSPP when it is not ready Current code will validate current plane and previous plane to confirm they can share a SSPP with multi-rect mode. The SSPP is al...
CVE-2025-40053
- EPSS 0.59%
- Veröffentlicht 28.10.2025 11:48:28
- Zuletzt bearbeitet 30.07.2026 06:24:08
In the Linux kernel, the following vulnerability has been resolved: net: dlink: handle copy_thresh allocation failure The driver did not handle failure of `netdev_alloc_skb_ip_align()`. If the allocation failed, dereferencing `skb->protocol` could ...
- EPSS 0.21%
- Veröffentlicht 28.10.2025 11:48:25
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: Squashfs: fix uninit-value in squashfs_get_parent Syzkaller reports a "KMSAN: uninit-value in squashfs_get_parent" bug. This is caused by open_by_handle_at() being called with a f...
CVE-2025-40043
- EPSS 0.29%
- Veröffentlicht 28.10.2025 11:48:22
- Zuletzt bearbeitet 30.07.2026 06:24:07
In the Linux kernel, the following vulnerability has been resolved: net: nfc: nci: Add parameter validation for packet data Syzbot reported an uninitialized value bug in nci_init_req, which was introduced by commit 5aca7966d2a7 ("Merge tag 'perf-to...
CVE-2025-40044
- EPSS 0.16%
- Veröffentlicht 28.10.2025 11:48:22
- Zuletzt bearbeitet 30.07.2026 06:24:07
In the Linux kernel, the following vulnerability has been resolved: fs: udf: fix OOB read in lengthAllocDescs handling When parsing Allocation Extent Descriptor, lengthAllocDescs comes from on-disk data and must be validated against the block size....
- EPSS 0.21%
- Veröffentlicht 28.10.2025 11:48:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix race condition in kprobe initialization causing NULL pointer dereference There is a critical race condition in kprobe initialization that can lead to NULL pointer dere...
- EPSS 0.22%
- Veröffentlicht 28.10.2025 11:48:17
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: Input: uinput - zero-initialize uinput_ff_upload_compat to avoid info leak Struct ff_effect_compat is embedded twice inside uinput_ff_upload_compat, contains internal padding. In p...
- EPSS 0.21%
- Veröffentlicht 28.10.2025 11:48:01
- Zuletzt bearbeitet 15.04.2026 00:35:42
In the Linux kernel, the following vulnerability has been resolved: pinctrl: check the return value of pinmux_ops::get_function_name() While the API contract in docs doesn't specify it explicitly, the generic implementation of the get_function_name...
CVE-2025-40026
- EPSS 0.16%
- Veröffentlicht 28.10.2025 09:32:33
- Zuletzt bearbeitet 30.07.2026 06:24:06
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O When completing emulation of instruction that generated a userspace exit for I/O, don't recheck L1 intercepts ...