CVE-2025-38591
- EPSS 0.19%
- Veröffentlicht 19.08.2025 17:15:36
- Zuletzt bearbeitet 14.09.2026 12:17:36
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject narrower access to pointer ctx fields The following BPF program, simplified from a syzkaller repro, causes a kernel warning: r0 = *(u8 *)(r1 + 169); exit; Wit...
CVE-2025-38579
- EPSS 0.16%
- Veröffentlicht 19.08.2025 17:15:35
- Zuletzt bearbeitet 30.07.2026 06:23:28
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix KMSAN uninit-value in extent_info usage KMSAN reported a use of uninitialized value in `__is_extent_mergeable()` and `__is_back_mergeable()` via the read extent tree pat...
CVE-2025-38581
- EPSS 0.17%
- Veröffentlicht 19.08.2025 17:15:35
- Zuletzt bearbeitet 09.01.2026 13:55:19
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix crash when rebind ccp device for ccp.ko When CONFIG_CRYPTO_DEV_CCP_DEBUGFS is enabled, rebinding the ccp device causes the following crash: $ echo '0000:0a:00.2'...
CVE-2025-38582
- EPSS 0.17%
- Veröffentlicht 19.08.2025 17:15:35
- Zuletzt bearbeitet 30.07.2026 06:23:28
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix double destruction of rsv_qp rsv_qp may be double destroyed in error flow, first in free_mr_init(), and then in hns_roce_exit(). Fix it by moving the free_mr_init() c...
CVE-2025-38583
- EPSS 0.16%
- Veröffentlicht 19.08.2025 17:15:35
- Zuletzt bearbeitet 09.01.2026 13:53:54
In the Linux kernel, the following vulnerability has been resolved: clk: xilinx: vcu: unregister pll_post only if registered correctly If registration of pll_post is failed, it will be set to NULL or ERR, unregistering same will fail with following...
CVE-2025-38584
- EPSS 0.16%
- Veröffentlicht 19.08.2025 17:15:35
- Zuletzt bearbeitet 30.07.2026 06:23:28
In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in padata_reorder that goes back to the initial commit. A reference count is taken at the start of the process in...
CVE-2025-38585
- EPSS 0.21%
- Veröffentlicht 19.08.2025 17:15:35
- Zuletzt bearbeitet 15.06.2026 10:16:27
In the Linux kernel, the following vulnerability has been resolved: staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() When gmin_get_config_var() calls efi.get_variable() and the EFI variable is larger than the expected buffer...
CVE-2025-38572
- EPSS 0.19%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 30.07.2026 06:23:27
In the Linux kernel, the following vulnerability has been resolved: ipv6: reject malicious packets in ipv6_gso_segment() syzbot was able to craft a packet with very long IPv6 extension headers leading to an overflow of skb->transport_header. This ...
CVE-2025-38574
- EPSS 0.36%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 30.07.2026 06:23:27
In the Linux kernel, the following vulnerability has been resolved: pptp: ensure minimal skb length in pptp_xmit() Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data on ppp_sync_txmung") fixed ppp_sync_txmunge() We need a similar fix ...
CVE-2025-38576
- EPSS 0.16%
- Veröffentlicht 19.08.2025 17:15:34
- Zuletzt bearbeitet 09.01.2026 14:15:23
In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: Make EEH driver device hotplug safe Multiple race conditions existed between the PCIe hotplug driver and the EEH driver, leading to a variety of kernel oopses of the s...