Posts of last 24 hours
2026年07月30日(現地時間)、米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。
https://jvn.jp/vu/JVNVU97496464/
https://buaq.net/go-432042.html
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.14.0. The affected element is the function nf_sk_lookup_slow_v4 of the component netfilter. The manipulation results in privilege escalation.
This vulnerability is reported as CVE-2025-22021. The attacker must have access to the local network to execute the attack. No exploit exists.
You should upgrade the affected component.
https://vuldb.com/vuln/304993
A vulnerability was found in Linux Kernel up to 6.12.22/6.13.10/6.14.1 and classified as critical. This issue affects the function PageTail of the component gup. Such manipulation leads to improper update of reference count.
This vulnerability is listed as CVE-2025-22034. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/305079
A vulnerability marked as problematic has been reported in Linux Kernel up to 6.14.1. Affected by this vulnerability is the function to_nfit_bus_uuid of the component acpi. Performing a manipulation results in incorrect type conversion.
This vulnerability is known as CVE-2025-22044. Access to the local network is required for this attack. No exploit is available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/305086
A vulnerability described as problematic has been identified in Linux Kernel up to 6.12.22/6.13.10/6.14.1. Affected by this issue is the function block_read_full_folio of the component exfat. Executing a manipulation can lead to race condition.
This vulnerability is handled as CVE-2025-22036. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/305087
A vulnerability has been found in Linux Kernel up to 6.14.1 and classified as critical. The affected element is the function dl_stid of the component nfsd. Performing a manipulation results in improper update of reference count.
This vulnerability is identified as CVE-2025-22025. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/305092
A vulnerability was found in Linux Kernel up to 6.1.133/6.6.86/6.12.22/6.13.10/6.14.1. It has been rated as problematic. Affected is the function num_subauth of the component ksmbd. This manipulation causes out-of-bounds read.
This vulnerability is registered as CVE-2025-22038. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/305096