CVE-2025-38509 – Apache Linux WiFi Invalid Channel Width Notification Vulnerability

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reject VHT opmode for unsupported channel widths VHT operating mode notifications are not defined for channel widths below 20 MHz. In particular, 5 MHz and 10 MHz are not valid under the VHT specification and must be rejected. Without this check, malformed notifications […]

CVE-2025-38508 – “SEV-SNP Linux Kernel Secure TSC Frequency Calculation Vulnerability”

In the Linux kernel, the following vulnerability has been resolved: x86/sev: Use TSC_FACTOR for Secure TSC frequency calculation When using Secure TSC, the GUEST_TSC_FREQ MSR reports a frequency based on the nominal P0 frequency, which deviates slightly (typically ~0.2%) from the actual mean TSC frequency due to clocking parameters. Over extended VM uptime, this discrepancy […]

CVE-2025-38507 – Nintendo Bluetooth HID Stall and Panic Vulnerability

The following table lists the changes that have been made to the CVE-2025-38507 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Aug. 16, 2025 Action […]

CVE-2025-38506 – Oracle KVM CPU Soft Lockup Vulnerability

In the Linux kernel, the following vulnerability has been resolved: KVM: Allow CPU to reschedule while setting per-page memory attributes When running an SEV-SNP guest with a sufficiently large amount of memory (1TB+), the host can experience CPU soft lockups when running an operation in kvm_vm_set_mem_attributes() to set memory attributes on the whole range of […]

CVE-2025-38505 – “Mwifiex STA Interface Disassociation Frame Validation”

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: discard erroneous disassoc frames on STA interface When operating in concurrent STA/AP mode with host MLME enabled, the firmware incorrectly sends disassociation frames to the STA interface when clients disconnect from the AP interface. This causes kernel warnings as the STA interface processes […]

CVE-2025-38504 – Linux Kernel io_uring ZCRX Use After Free

The following table lists the changes that have been made to the CVE-2025-38504 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Aug. 16, 2025 Action […]

CVE-2025-38502 – Linux Kernel BPF Cgroup Local Storage Out-of-Bounds Access

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted via tail calls. Given two programs each utilizing a cgroup local storage with a different value size, and one program doing a tail call […]

CVE-2025-8719 – WordPress gTranslate Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-8719 Published : Aug. 16, 2025, 9:15 a.m. | 1 hour, 24 minutes ago Description : The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_lang’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible […]