CVE-2025-22038
- EPSS 0.56%
- Veröffentlicht 16.04.2025 14:11:56
- Zuletzt bearbeitet 30.07.2026 06:22:05
In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate zero num_subauth before sub_auth is accessed Access psid->sub_auth[psid->num_subauth - 1] without checking if num_subauth is non-zero leads to an out-of-bounds read...
CVE-2025-22039
- EPSS 0.68%
- Veröffentlicht 16.04.2025 14:11:56
- Zuletzt bearbeitet 14.09.2026 12:17:35
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing boun...
CVE-2025-22037
- EPSS 66.42%
- Veröffentlicht 16.04.2025 14:11:55
- Zuletzt bearbeitet 08.10.2026 00:46:56
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in alloc_preauth_hash() The Client send malformed smb2 negotiate request. ksmbd return error response. Subsequently, the client can send smb2 se...
- EPSS 0.19%
- Veröffentlicht 16.04.2025 14:11:54
- Zuletzt bearbeitet 30.07.2026 06:22:04
In the Linux kernel, the following vulnerability has been resolved: exfat: fix random stack corruption after get_block When get_block is called with a buffer_head allocated on the stack, such as do_mpage_readpage, stack corruption due to buffer_hea...
CVE-2025-22035
- EPSS 0.29%
- Veröffentlicht 16.04.2025 14:11:53
- Zuletzt bearbeitet 03.11.2025 20:17:38
In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in print_graph_function_flags during tracer switching Kairui reported a UAF issue in print_graph_function_flags() during ftrace stress testing [1]. This...
CVE-2025-22033
- EPSS 0.2%
- Veröffentlicht 16.04.2025 14:11:52
- Zuletzt bearbeitet 03.11.2025 20:17:38
In the Linux kernel, the following vulnerability has been resolved: arm64: Don't call NULL in do_compat_alignment_fixup() do_alignment_t32_to_handler() only fixes up alignment faults for specific instructions; it returns NULL otherwise (e.g. LDREX)...
CVE-2025-22027
- EPSS 0.15%
- Veröffentlicht 16.04.2025 14:11:48
- Zuletzt bearbeitet 03.11.2025 20:17:38
In the Linux kernel, the following vulnerability has been resolved: media: streamzap: fix race between device disconnection and urb callback Syzkaller has reported a general protection fault at function ir_raw_event_store_with_filter(). This crash ...
CVE-2025-22028
- EPSS 0.19%
- Veröffentlicht 16.04.2025 14:11:48
- Zuletzt bearbeitet 28.10.2025 19:05:26
In the Linux kernel, the following vulnerability has been resolved: media: vimc: skip .s_stream() for stopped entities Syzbot reported [1] a warning prompted by a check in call_s_stream() that checks whether .s_stream() operation is warranted for u...
CVE-2025-22026
- EPSS 0.2%
- Veröffentlicht 16.04.2025 14:11:47
- Zuletzt bearbeitet 06.04.2026 13:40:05
In the Linux kernel, the following vulnerability has been resolved: nfsd: don't ignore the return code of svc_proc_register() Currently, nfsd_proc_stat_init() ignores the return value of svc_proc_register(). If the procfile creation fails, then the...
CVE-2025-22025
- EPSS 0.55%
- Veröffentlicht 16.04.2025 14:11:46
- Zuletzt bearbeitet 30.07.2026 06:22:04
In the Linux kernel, the following vulnerability has been resolved: nfsd: put dl_stid if fail to queue dl_recall Before calling nfsd4_run_cb to queue dl_recall to the callback_wq, we increment the reference count of dl_stid. We expect that after th...