CVE-2025-38509 – Apache Linux WiFi Invalid Channel Width Notification Vulnerability
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reject VHT opmode for unsupported channel widths VHT operating mode notifications are not defined for channel widths below 20 MHz. In particular, 5 MHz and 10 MHz are not valid under the VHT specification and must be rejected. Without this check, malformed notifications […]
CVE-2025-38508 – “SEV-SNP Linux Kernel Secure TSC Frequency Calculation Vulnerability”
In the Linux kernel, the following vulnerability has been resolved: x86/sev: Use TSC_FACTOR for Secure TSC frequency calculation When using Secure TSC, the GUEST_TSC_FREQ MSR reports a frequency based on the nominal P0 frequency, which deviates slightly (typically ~0.2%) from the actual mean TSC frequency due to clocking parameters. Over extended VM uptime, this discrepancy […]
CVE-2025-38507 – Nintendo Bluetooth HID Stall and Panic Vulnerability
The following table lists the changes that have been made to the CVE-2025-38507 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Aug. 16, 2025 Action […]
CVE-2025-38506 – Oracle KVM CPU Soft Lockup Vulnerability
In the Linux kernel, the following vulnerability has been resolved: KVM: Allow CPU to reschedule while setting per-page memory attributes When running an SEV-SNP guest with a sufficiently large amount of memory (1TB+), the host can experience CPU soft lockups when running an operation in kvm_vm_set_mem_attributes() to set memory attributes on the whole range of […]
CVE-2025-38505 – “Mwifiex STA Interface Disassociation Frame Validation”
In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: discard erroneous disassoc frames on STA interface When operating in concurrent STA/AP mode with host MLME enabled, the firmware incorrectly sends disassociation frames to the STA interface when clients disconnect from the AP interface. This causes kernel warnings as the STA interface processes […]
CVE-2025-38504 – Linux Kernel io_uring ZCRX Use After Free
The following table lists the changes that have been made to the CVE-2025-38504 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Aug. 16, 2025 Action […]
CVE-2025-38503 – Here is the title: Apache Linux Btrfs Free Space Tree Vulnerability
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix assertion when building free space tree When building the free space tree with the block group tree feature enabled, we can hit an assertion failure like this: BTRFS info (device loop0 state M): rebuilding free space tree assertion failed: ret == 0, in […]
CVE-2025-38502 – Linux Kernel BPF Cgroup Local Storage Out-of-Bounds Access
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted via tail calls. Given two programs each utilizing a cgroup local storage with a different value size, and one program doing a tail call […]
CVE-2025-8719 – WordPress gTranslate Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-8719 Published : Aug. 16, 2025, 9:15 a.m. | 1 hour, 24 minutes ago Description : The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_lang’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible […]
CVE-2025-8464 – WordPress Contact Form 7 Drag and Drop Multiple File Upload Directory Traversal Vulnerability
CVE ID : CVE-2025-8464 Published : Aug. 16, 2025, 8:15 a.m. | 24 minutes ago Description : The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to […]