Vulnerabilities

  

CVE-2025-14259 | Jihai Jshop MiniProgram Mall System 2.9.0 /index.php/api.html cat_id sql injection

A vulnerability labeled as critical has been found in Jihai Jshop MiniProgram Mall System 2.9.0. Affected by this issue is

  

CVE-2025-40293 | Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 iommufd divide by zero

A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7. Impacted is an unknown function of

  

CVE-2025-40297 | Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 net use after free

A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7. The affected element is an unknown

  

CVE-2025-40298 | Linux Kernel up to 6.17.7 gve ptp_clock_settime null pointer dereference

A vulnerability marked as critical has been reported in Linux Kernel up to 6.17.7. The impacted element is the function

  

CVE-2025-40299 | Linux Kernel up to 6.17.7 gve ptp_clock_gettime null pointer dereference

A vulnerability described as critical has been identified in Linux Kernel up to 6.17.7. This affects the function ptp_clock_gettime of

  

CVE-2025-40301 | Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 Bluetooth hci_cmd_complete_evt privilege escalation

A vulnerability classified as critical has been found in Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7. This impacts the function hci_cmd_complete_evt of

  

CVE-2025-40302 | Linux Kernel up to 6.12.57/6.17.7 vb2_ioctl_remove_bufs buffer overflow

A vulnerability classified as critical was found in Linux Kernel up to 6.12.57/6.17.7. Affected is the function vb2_ioctl_remove_bufs. The manipulation

  

CVE-2025-40304 | Linux Kernel up to 6.17.7 bit_putcs out-of-bounds write

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.17.7. Affected by this vulnerability

  

CVE-2025-40307 | Linux Kernel up to 6.12.57/6.17.7 exfat_mkdir allocation of resources

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.57/6.17.7. Affected by this issue is

  

CVE-2025-40309 | Linux Kernel up to 6.17.7 Bluetooth net/bluetooth/sco.c sco_conn_free use after free

A vulnerability has been found in Linux Kernel up to 6.17.7 and classified as critical. This affects the function sco_conn_free

  

CVE-2025-40310 | Linux Kernel up to 6.6.116/6.12.57/6.17.7 amdgpu_amdkfd_device_fini_sw null pointer dereference

A vulnerability was found in Linux Kernel up to 6.6.116/6.12.57/6.17.7 and classified as critical. This vulnerability affects the function amdgpu_amdkfd_device_fini_sw.

  

CVE-2025-40311 | Linux Kernel up to 6.6.116/6.12.57/6.17.7 dma_alloc_coherent allocation of resources

A vulnerability was found in Linux Kernel up to 6.6.116/6.12.57/6.17.7. It has been classified as critical. This issue affects the

  

CVE-2025-40315 | Linux Kernel up to 6.17.7 ffs_func_eps_enable null pointer dereference

A vulnerability was found in Linux Kernel up to 6.17.7. It has been declared as critical. Impacted is the function

  

CVE-2025-40318 | Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 Bluetooth hci_cmd_sync_dequeue_once use after free

A vulnerability was found in Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7. It has been rated as critical. The affected element is

  

CVE-2025-40320 | Linux Kernel up to 6.6.116/6.12.57/6.17.7 smb smb2_query_info_compound use after free

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.116/6.12.57/6.17.7. The impacted element is the function

  

CVE-2025-40322 | Linux Kernel up to 6.17.7 fbdev bit_putcs_aligned out-of-bounds

A vulnerability identified as critical has been detected in Linux Kernel up to 6.17.7. This affects the function bit_putcs_aligned of

  

CVE-2025-40324 | Linux Kernel up to 6.17.7 NFSD nfsd4_read_release denial of service

A vulnerability labeled as critical has been found in Linux Kernel up to 6.17.7. This impacts the function nfsd4_read_release of

  

CVE-2025-40326 | Linux Kernel up to 6.17.7 time_deleg state issue

A vulnerability marked as critical has been reported in Linux Kernel up to 6.17.7. Affected is the function time_deleg. The

  

CVE-2025-40295 | Linux Kernel up to 6.17.7 fscrypt fs/crypto/inline_crypt.c set_init_blocksize allocation of resources

A vulnerability described as critical has been identified in Linux Kernel up to 6.17.7. Affected by this vulnerability is the

  

CVE-2025-14244 | GreenCMS 2.3.0603 Menu Management Page CustomController.class.php Link cross site scripting

A vulnerability classified as problematic has been found in GreenCMS 2.3.0603. Affected by this issue is some unknown functionality of

  

CVE-2025-14245 | IdeaCMS up to 1.8 Coupon.php whereRaw params sql injection

A vulnerability classified as critical was found in IdeaCMS up to 1.8. This affects the function whereRaw of the file

  

CVE-2025-14246 | code-projects Simple Shopping Cart 1.0 /Customers/settings.php user_id sql injection

A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown

  

CVE-2025-14247 | code-projects Simple Shopping Cart 1.0 /Admin/additems.php item_name sql injection

A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown

  

CVE-2025-14248 | code-projects Simple Shopping Cart 1.0 /adminlogin.php admin_username sql injection

A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Impacted is an unknown function

  

CVE-2025-14249 | code-projects Online Ordering System 1.0 /user_school.php product_id sql injection

A vulnerability was found in code-projects Online Ordering System 1.0 and classified as critical. The affected element is an unknown

  

CVE-2025-14250 | code-projects Online Ordering System 1.0 /user_contact.php Name sql injection

A vulnerability was found in code-projects Online Ordering System 1.0. It has been classified as critical. The impacted element is

  

CVE-2025-14251 | code-projects Online Ordering System 1.0 Admin Login /admin/ Username sql injection

A vulnerability was found in code-projects Online Ordering System 1.0. It has been declared as critical. This affects an unknown

  

CVE-2022-50615 | Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1 snr_uncore_mmio_map reference count

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.10.162/5.15.85/6.0.15/6.1.1. Affected is the function

  

CVE-2022-50618 | Linux Kernel up to 6.1.1 mmc_add_host return value

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.1. Affected by this vulnerability is

  

CVE-2022-50619 | Linux Kernel up to 5.15.76/6.0.6 kfd_mem_dmamap_userptr memory leak

A vulnerability has been found in Linux Kernel up to 5.15.76/6.0.6 and classified as critical. Affected by this issue is

  

CVE-2022-50623 | Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2 on 32-bit fpga dfl_feature_ioctl_set_irq integer overflow

A vulnerability was found in Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2 on 32-bit and classified as critical. This affects the function

  

CVE-2023-53744 | Linux Kernel up to 5.10.179/5.15.110/6.1.27/6.2.14/6.3.1 soc wkup_m3_ipc_get reference count

A vulnerability was found in Linux Kernel up to 5.10.179/5.15.110/6.1.27/6.2.14/6.3.1. It has been classified as critical. This vulnerability affects the

  

CVE-2022-50626 | Linux Kernel up to 6.1.1 dvb_usb_adapter_init num_adapters_initalized reference count

A vulnerability was found in Linux Kernel up to 6.1.1. It has been declared as critical. This issue affects the

  

CVE-2023-53745 | Linux Kernel up to 6.2.4 uml_parse_vector_ifspec return value

A vulnerability was found in Linux Kernel up to 6.2.4. It has been rated as critical. Impacted is the function

  

CVE-2022-50629 | Linux Kernel up to 6.2.2 wifi rsi_coex_attach memory leak

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.2.2. The affected element is the function

  

CVE-2022-50622 | Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2 ext4 ext4_fc_record_modified_inode memory leak

A vulnerability identified as critical has been detected in Linux Kernel up to 5.10.149/5.15.74/5.19.16/6.0.2. The impacted element is the function

  

CVE-2023-53746 | Linux Kernel up to 5.4.239/5.10.176/5.15.105/6.1.22/6.2.9 vfio_ap null pointer dereference

A vulnerability labeled as critical has been found in Linux Kernel up to 5.4.239/5.10.176/5.15.105/6.1.22/6.2.9. This affects the function vfio_ap. Such

  

CVE-2023-53747 | Linux Kernel up to 6.3.3 vc_screen.c vcs_write use after free

A vulnerability marked as critical has been reported in Linux Kernel up to 6.3.3. This impacts the function vcs_write of

  

CVE-2022-50624 | Linux Kernel up to 4.19.263/5.4.222/5.10.152/5.15.76/6.0.6 netsec_register_mdio reference count

A vulnerability described as critical has been identified in Linux Kernel up to 4.19.263/5.4.222/5.10.152/5.15.76/6.0.6. Affected is the function netsec_register_mdio. Executing

  

CVE-2023-53762 | Linux Kernel up to 6.4.15/6.5.2 net/bluetooth/hci_sync.c hci_sync use after free

A vulnerability classified as critical has been found in Linux Kernel up to 6.4.15/6.5.2. Affected by this vulnerability is the

  

CVE-2023-53752 | Linux Kernel up to 6.1.53/6.4.15/6.5.2 net net/core/skbuff.c kmalloc_reserve integer overflow

A vulnerability classified as critical was found in Linux Kernel up to 6.1.53/6.4.15/6.5.2. Affected by this issue is the function

  

CVE-2023-53761 | Linux Kernel up to 5.4.243/5.10.180/5.15.112/6.1.29/6.3.3 Usbtmc Driver drivers/usb/core/urb.c usb_submit_urb privilege escalation

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 5.4.243/5.10.180/5.15.112/6.1.29/6.3.3. This affects the function

  

CVE-2025-40303 | Linux Kernel up to 6.6.116/6.12.57/6.17.7 btrfs_bio::end_io use after free

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.116/6.12.57/6.17.7. This vulnerability affects the function

  

CVE-2023-53763 | Linux Kernel up to 6.1.52/6.4.15/6.5.2 UBSAN fs/f2fs/f2fs.h array index

A vulnerability has been found in Linux Kernel up to 6.1.52/6.4.15/6.5.2 and classified as critical. This issue affects some unknown

  

CVE-2025-40323 | Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 fbcon do_unregister_framebuffer fb_display[] use after free

A vulnerability was found in Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 and classified as critical. Impacted is the function do_unregister_framebuffer of

  

CVE-2023-53749 | Linux Kernel up to 6.2.15 clear_page_64.S clear_user_rep_good memory corruption

A vulnerability was found in Linux Kernel up to 6.2.15. It has been classified as critical. The affected element is

  

CVE-2023-53754 | Linux Kernel up to 6.3.1 scsi lpfc_sli4_pci_mem_setup null pointer dereference

A vulnerability was found in Linux Kernel up to 6.3.1. It has been declared as critical. The impacted element is

  

CVE-2023-53755 | Linux Kernel up to 6.1.15/6.2.2 PTDMA Driver pt_issue_pending null pointer dereference

A vulnerability was found in Linux Kernel up to 6.1.15/6.2.2. It has been rated as critical. This affects the function

  

CVE-2023-53756 | Linux Kernel up to 5.10.174/5.15.102/6.1.15/6.2.2 vmx_vcpu_create null pointer dereference

A vulnerability categorized as critical has been discovered in Linux Kernel up to 5.10.174/5.15.102/6.1.15/6.2.2. This impacts the function vmx_vcpu_create. Such

  

CVE-2023-53758 | Linux Kernel up to 6.1.27/6.2.14/6.3.1 remove privilege escalation

A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.27/6.2.14/6.3.1. Affected is the function remove. Performing

  

CVE-2023-53759 | Linux Kernel up to 6.1.36/6.3.10/6.4.0 HID hidraw_open reference count

A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.36/6.3.10/6.4.0. Affected by this vulnerability is the

  

CVE-2023-53765 | Linux Kernel up to 6.1.15/6.2.2 __kmem_cache_shutdown stack-based overflow

A vulnerability marked as critical has been reported in Linux Kernel up to 6.1.15/6.2.2. Affected by this issue is the

  

CVE-2023-53768 | Linux Kernel up to 6.1.39/6.4.4 regmap_add_irq_chip_fwnode memory corruption

A vulnerability described as critical has been identified in Linux Kernel up to 6.1.39/6.4.4. This affects the function regmap_add_irq_chip_fwnode. The

  

CVE-2023-53769 | Linux Kernel up to 6.1.27/6.2.14/6.3.1 message integrity

A vulnerability classified as critical has been found in Linux Kernel up to 6.1.27/6.2.14/6.3.1. This vulnerability affects unknown code. This

  

CVE-2025-40292 | Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 virtio-net null pointer dereference

A vulnerability classified as critical was found in Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7. This issue affects some unknown processing of

  

CVE-2025-40294 | Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7 Bluetooth parse_adv_monitor_pattern out-of-bounds

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.158/6.6.116/6.12.57/6.17.7. Impacted is the function

  

CVE-2025-40296 | Linux Kernel up to 6.17.7 regulator_unregister reference count

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.17.7. The affected element is the

  

CVE-2025-40305 | Linux Kernel up to 6.12.57/6.17.7 p9_read_work privilege escalation

A vulnerability has been found in Linux Kernel up to 6.12.57/6.17.7 and classified as problematic. The impacted element is the

  

CVE-2025-40306 | Linux Kernel up to 6.17.7 xattr_key buffer overflow

A vulnerability was found in Linux Kernel up to 6.17.7 and classified as critical. This affects the function xattr_key. The

  

CVE-2025-40308 | Linux Kernel up to 6.17.7 BCSP Protocol bcsp_recv null pointer dereference

A vulnerability was found in Linux Kernel up to 6.17.7. It has been classified as critical. This impacts the function

  

CVE-2025-40312 | Linux Kernel up to 6.17.7 jfs privilege escalation

A vulnerability was found in Linux Kernel up to 6.17.7. It has been declared as critical. Affected is an unknown

  

CVE-2025-40313 | Linux Kernel up to 5.15.196/6.1.158/6.6.116/6.12.57/6.17.7 ntfs3 may_open privilege escalation

A vulnerability was found in Linux Kernel up to 5.15.196/6.1.158/6.6.116/6.12.57/6.17.7. It has been rated as critical. Affected by this vulnerability

  

CVE-2025-40314 | Linux Kernel up to 5.15.196/6.1.158/6.6.116/6.12.57/6.17.7 cdns3 __cdnsp_gadget_init initialization

A vulnerability categorized as critical has been discovered in Linux Kernel up to 5.15.196/6.1.158/6.6.116/6.12.57/6.17.7. Affected by this issue is the

  

CVE-2025-40316 | Linux Kernel up to 6.6.116/6.12.57/6.17.7 mediatek bind use after free

A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.116/6.12.57/6.17.7. This affects the function bind of

  

CVE-2025-40317 | Linux Kernel up to 6.17.7 wcd934x_codec_parse_data denial of service

A vulnerability labeled as problematic has been found in Linux Kernel up to 6.17.7. This vulnerability affects the function wcd934x_codec_parse_data.

  

CVE-2025-40319 | Linux Kernel up to 6.17.7 bpf bpf_ringbuf_commit buffer overflow

A vulnerability marked as critical has been reported in Linux Kernel up to 6.17.7. This issue affects the function bpf_ringbuf_commit

  

CVE-2025-40321 | Linux Kernel up to 6.17.7 P2P Interface init_completion null pointer dereference

A vulnerability described as critical has been identified in Linux Kernel up to 6.17.7. Impacted is the function init_completion of

  

CVE-2023-53748 | Linux Kernel up to 6.1.29/6.3.3 queue_setup out-of-bounds

A vulnerability classified as critical has been found in Linux Kernel up to 6.1.29/6.3.3. The affected element is the function

  

CVE-2023-53750 | Linux Kernel up to 6.3.12/6.4.3 pinctrl num_configs out-of-bounds

A vulnerability classified as critical was found in Linux Kernel up to 6.3.12/6.4.3. The impacted element is the function num_configs

  

CVE-2023-53751 | Linux Kernel up to 6.1.27/6.2.14/6.3.1 cifs hostname use after free

A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.27/6.2.14/6.3.1. This affects the function

  

CVE-2023-53753 | Linux Kernel up to 6.1.15/6.2.2 out-of-bounds

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.15/6.2.2. This impacts an unknown function.

  

CVE-2023-53757 | Linux Kernel up to 6.2.2 irq-mvebu-gicp of_irq_find_parent reference count

A vulnerability has been found in Linux Kernel up to 6.2.2 and classified as critical. Affected is the function of_irq_find_parent

  

CVE-2023-53760 | Linux Kernel up to 6.3.2 ufshcd_err_handler deadlock

A vulnerability was found in Linux Kernel up to 6.3.2 and classified as critical. Affected by this vulnerability is the

  

CVE-2023-53764 | Linux Kernel up to 6.3.3 peer.c ath12k_peer_find_by_id assertion

A vulnerability was found in Linux Kernel up to 6.3.3. It has been classified as critical. Affected by this issue

  

CVE-2023-53766 | Linux Kernel up to 6.4.6 FS null pointer dereference

A vulnerability was found in Linux Kernel up to 6.4.6. It has been declared as critical. This affects an unknown

  

CVE-2023-53767 | Linux Kernel up to 6.3.3 wifi ath12k_qmi_driver_event_work memory leak

A vulnerability was found in Linux Kernel up to 6.3.3. It has been rated as critical. This vulnerability affects the

  

CVE-2025-40291 | Linux Kernel up to 6.17.7 io_uring io_estimate_bvec_size privilege escalation

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17.7. This issue affects the function io_estimate_bvec_size

Debian Trixie: FFmpeg Critical Denial of Service and Code Exec DSA-6073-1
  

Debian Trixie: FFmpeg Critical Denial of Service and Code Exec DSA-6073-1

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the

  

CVE-2025-14229 | SourceCodester Inventory Management System 1.0 SVC Report Export csv injection

A vulnerability classified as critical was found in SourceCodester Inventory Management System 1.0. The affected element is an unknown function

  

CVE-2025-14230 | code-projects Daily Time Recording System 4.5.0 /admin/add_payroll.php detail_Id sql injection

A vulnerability, which was classified as critical, has been found in code-projects Daily Time Recording System 4.5.0. The impacted element

  

CVE-2025-14227 | Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958 /edit.php sql injection

A vulnerability described as critical has been identified in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This issue affects some unknown processing

  

CVE-2025-14228 | Yealink SIP-T21P E2 52.84.0.15 Local Directory Page cross site scripting

A vulnerability classified as problematic has been found in Yealink SIP-T21P E2 52.84.0.15. Impacted is an unknown function of the

Debian: libpng Critical DoS Update DLA-4396-1 CVE-2025-64505
  

Debian: libpng Critical DoS Update DLA-4396-1 CVE-2025-64505

Multiple vulnerabilties have been found in libpng, the official PNG reference library, allowing information disclosure via out-of-bounds read, denial of

  

CVE-2025-14220 | ORICO CD3510 1.9.12 File Upload path traversal

A vulnerability was found in ORICO CD3510 1.9.12. It has been classified as critical. This affects an unknown function of

  

CVE-2025-14221 | SourceCodester Online Banking System 1.0 /?page=user First Name/Last Name cross site scripting

A vulnerability was found in SourceCodester Online Banking System 1.0. It has been declared as problematic. This impacts an unknown

  

CVE-2025-14222 | code-projects Employee Profile Management System 1.0 print_personnel_report.php per_id sql injection

A vulnerability was found in code-projects Employee Profile Management System 1.0. It has been rated as critical. Affected is an

  

CVE-2025-14223 | code-projects Simple Leave Manager 1.0 /request.php staff_id sql injection

A vulnerability categorized as critical has been discovered in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an

  

CVE-2025-14224 | Yottamaster DM2/DM3/DM200 up to 1.2.23/1.9.12 File Upload path traversal

A vulnerability identified as critical has been detected in Yottamaster DM2, DM3 and DM200 up to 1.2.23/1.9.12. Affected by this

  

CVE-2025-14225 | D-Link DCS-930L 1.15.04 alphapd /setSystemAdmin AdminID command injection

A vulnerability labeled as critical has been found in D-Link DCS-930L 1.15.04. This affects an unknown part of the file

  

CVE-2025-14226 | itsourcecode Student Management System 1.0 /edit_user.php fname sql injection

A vulnerability marked as critical has been reported in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of

  

CVE-2025-14214 | itsourcecode Student Information System 1.0 /section_edit1.php ID sql injection

A vulnerability classified as critical has been found in itsourcecode Student Information System 1.0. This affects an unknown part of

  

CVE-2025-14215 | code-projects Currency Exchange System 1.0 /edit.php ID sql injection

A vulnerability classified as critical was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the

  

CVE-2025-14216 | code-projects Currency Exchange System 1.0 /viewserial.php ID sql injection

A vulnerability, which was classified as critical, has been found in code-projects Currency Exchange System 1.0. This issue affects some

  

CVE-2025-14217 | code-projects Currency Exchange System 1.0 /edittrns.php ID sql injection

A vulnerability, which was classified as critical, was found in code-projects Currency Exchange System 1.0. Impacted is an unknown function

  

CVE-2025-14218 | code-projects Currency Exchange System 1.0 /editotheraccount.php ID sql injection

A vulnerability has been found in code-projects Currency Exchange System 1.0 and classified as critical. The affected element is an

  

CVE-2025-14219 | Campcodes Retro Basketball Shoes Online Store 1.0 /admin/admin_running.php product_image unrestricted upload

A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0 and classified as critical. The impacted element is

Fedora 42: tinygltf Update 2.9.7 Advisory FEDORA-2025-ac8ed4a110
  

Fedora 42: tinygltf Update 2.9.7 Advisory FEDORA-2025-ac8ed4a110

Update to 2.9.7LinuxSecurity – Security AdvisoriesRead More

  

CVE-2025-40281 | Linux Kernel up to 6.17.8 sctp net/sctp/transport.c out-of-bounds

A vulnerability was found in Linux Kernel up to 6.17.8. It has been rated as critical. Affected by this issue

  

CVE-2025-40269 | Linux Kernel up to 6.17.8 ALSA buffer overflow (EUVD-2025-201586)

A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17.8. This affects an unknown part of

  

CVE-2025-40280 | Linux Kernel up to 295c9b554f6dfcd2d368fae6e6fa22ee5b79c123 spinlock_api_smp.h tipc_mon_reinit_self monitors[] use after free

A vulnerability identified as critical has been detected in Linux Kernel up to 295c9b554f6dfcd2d368fae6e6fa22ee5b79c123. This vulnerability affects the function tipc_mon_reinit_self