CVE-2025-21669 – “Linux Kernel Virtio Vsock NULL Pointer Dereference”
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been de-assigned or assigned to another transport, we must discard any packets received because they are not expected and would cause issues when we access vsk->transport. A possible scenario is described by Hyunwoo Kim […]
CVE-2025-21677 – Vulnerability Title: Linux pfcp Newlink devices Remote Reference Leak
In the Linux kernel, the following vulnerability has been resolved: pfcp: Destroy device along with udp socket’s netns dismantle. pfcp_newlink() links the device to a list in dev_net(dev) instead of net, where a udp tunnel socket is created. Even when net is removed, the device stays alive on dev_net(dev). Then, removing net triggers the splat […]
CVE-2025-21676 – Linux Fec Network Driver Null Pointer Vulnerability
The following table lists the changes that have been made to the CVE-2025-21676 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jan. 31, 2025 Action […]
CVE-2025-21675 – Mellanox Technologies mlx5 Multiple Null Pointer Dereference Vulnerability
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clear port select structure when fail to create Clear the port select structure on error so no stale values left after definers are destroyed. That’s because the mlx5_lag_destroy_definers() always try to destroy all lag definers in the tt_map, so in the flow below lag […]
CVE-2025-21674 – Here is the title: “_checks-linux-mellanox-mlx5_core-xfrm-ipsec-tunnel-mode-hardcoded-lock-order-vulnerability”
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel Attempt to enable IPsec packet offload in tunnel mode in debug kernel generates the following kernel panic, which is happening due to two issues: 1. In SA add section, the should be _bh() variant when marking […]
CVE-2025-21672 – Linux Kernel AFS Lock Holding Vulnerability
The following table lists the changes that have been made to the CVE-2025-21672 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jan. 31, 2025 Action […]
CVE-2025-21673 – Linux SMB Client Double Free Vulnerability
The following table lists the changes that have been made to the CVE-2025-21673 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jan. 31, 2025 Action […]
CVE-2025-21670 – “Linux Kernel Vsock Transport NULL Pointer Dereference Vulnerability in BPF”
In the Linux kernel, the following vulnerability has been resolved: vsock/bpf: return early if transport is not assigned Some of the core functions can only be called if the transport has been assigned. As Michal reported, a socket might have the transport at NULL, for example after a failed connect(), causing the following trace: BUG: […]
CVE-2025-21671 – “Linux kernel Zram Use-After-Free”
The following table lists the changes that have been made to the CVE-2025-21671 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jan. 31, 2025 Action […]
CVE-2025-21668 – NXP i.MX8MP Linux PM Domain Detach Buffer Overflow Vulnerability
The following table lists the changes that have been made to the CVE-2025-21668 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Jan. 31, 2025 Action […]