CVE-2025-23159
- EPSS 0.21%
- Veröffentlicht 01.05.2025 12:55:44
- Zuletzt bearbeitet 30.07.2026 06:22:18
In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add a check to handle OOB in sfr region sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made high...
CVE-2025-23158
- EPSS 0.21%
- Veröffentlicht 01.05.2025 12:55:43
- Zuletzt bearbeitet 30.07.2026 06:22:17
In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add check to handle incorrect queue size qsize represents size of shared queued between driver and video firmware. Firmware can modify this value to an invalid l...
CVE-2025-23150
- EPSS 0.2%
- Veröffentlicht 01.05.2025 12:55:38
- Zuletzt bearbeitet 30.07.2026 06:22:16
In the Linux kernel, the following vulnerability has been resolved: ext4: fix off-by-one error in do_split Syzkaller detected a use-after-free issue in ext4_insert_dentry that was caused by out-of-bounds access due to incorrect splitting in do_spli...
CVE-2025-23143
- EPSS 0.2%
- Veröffentlicht 01.05.2025 12:55:33
- Zuletzt bearbeitet 14.07.2026 13:17:32
In the Linux kernel, the following vulnerability has been resolved: net: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod. When I ran the repro [0] and waited a few seconds, I observed two LOCKDEP splats: a warning immediately follow...
CVE-2025-23142
- EPSS 0.21%
- Veröffentlicht 01.05.2025 12:55:32
- Zuletzt bearbeitet 30.07.2026 06:22:16
In the Linux kernel, the following vulnerability has been resolved: sctp: detect and prevent references to a freed transport in sendmsg sctp_sendmsg() re-uses associations and transports when possible by doing a lookup based on the socket endpoint ...
CVE-2025-23141
- EPSS 0.2%
- Veröffentlicht 01.05.2025 12:55:31
- Zuletzt bearbeitet 30.07.2026 06:22:16
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses Acquire a lock on kvm->srcu when userspace is getting MP state to handle a rather extreme edge case wher...
CVE-2025-37838
- EPSS 0.21%
- Veröffentlicht 18.04.2025 14:20:55
- Zuletzt bearbeitet 03.11.2025 20:18:37
In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition In the ssi_protocol_probe() function, &ssi->work is bound with ssip_xmit_work(), In...
CVE-2025-37925
- EPSS 0.25%
- Veröffentlicht 18.04.2025 07:01:29
- Zuletzt bearbeitet 03.11.2025 18:15:55
In the Linux kernel, the following vulnerability has been resolved: jfs: reject on-disk inodes of an unsupported type Syzbot has reported the following BUG: kernel BUG at fs/inode.c:668! Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 3...
CVE-2025-37785
- EPSS 0.28%
- Veröffentlicht 18.04.2025 07:01:27
- Zuletzt bearbeitet 04.08.2026 11:22:43
In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bounds read (la...
CVE-2025-23136
- EPSS 0.2%
- Veröffentlicht 16.04.2025 14:13:16
- Zuletzt bearbeitet 14.07.2026 13:17:31
In the Linux kernel, the following vulnerability has been resolved: thermal: int340x: Add NULL check for adev Not all devices have an ACPI companion fwnode, so adev might be NULL. This is similar to the commit cd2fd6eab480 ("platform/x86: int3472: ...