Aggregator
Миллиард лет во тьме, вспышка возле Солнца и… Межзвездная комета выдала секреты других планет и навсегда ушла за орбиту Юпитера
3 days 16 hours ago
Астрономы проанализировали глубинный состав 3I/ATLAS.
Крупнейшее исследование древней ДНК показало ускорение эволюции человека за последние 10 тысяч лет
3 days 17 hours ago
Крупнейший на сегодня анализ ДНК показал то, о чём учёные даже не подозревали.
CVE-2025-38149 | Linux Kernel up to 6.6.93/6.12.33/6.15.2 phy_detach null pointer dereference (EUVD-2025-19794 / Nessus ID 265934)
3 days 18 hours ago
A vulnerability was found in Linux Kernel up to 6.6.93/6.12.33/6.15.2 and classified as critical. This vulnerability affects the function phy_detach. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2025-38149. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-38150 | Linux Kernel up to 6.15.2 af_packet kernel/locking/mutex.c (EUVD-2025-19793 / WID-SEC-2025-1452)
3 days 18 hours ago
A vulnerability was found in Linux Kernel up to 6.15.2. It has been rated as problematic. The affected element is an unknown function of the file kernel/locking/mutex.c of the component af_packet. Performing a manipulation results in improper locking.
This vulnerability is reported as CVE-2025-38150. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-38147 | Linux Kernel up to 6.15.2 calipso txopt_get null pointer dereference (EUVD-2025-19796 / Nessus ID 243500)
3 days 18 hours ago
A vulnerability was found in Linux Kernel up to 6.15.2. It has been classified as critical. Affected by this issue is the function txopt_get of the component calipso. The manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2025-38147. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-38148 | Linux Kernel up to 6.1.141/6.6.93/6.12.33/6.15.2 net memory leak (EUVD-2025-19795 / Nessus ID 249177)
3 days 18 hours ago
A vulnerability has been found in Linux Kernel up to 6.1.141/6.6.93/6.12.33/6.15.2 and classified as critical. This affects an unknown part of the component net. The manipulation leads to memory leak.
This vulnerability is listed as CVE-2025-38148. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2025-38145 | Linux Kernel up to 6.15.2 soc aspeed_lpc_enable_snoop null pointer dereference (EUVD-2025-19798 / Nessus ID 249177)
3 days 18 hours ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.15.2. Affected by this vulnerability is the function aspeed_lpc_enable_snoop of the component soc. Performing a manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2025-38145. The attack can only be performed from the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-38146 | Linux Kernel up to 6.15.2 openvswitch __be32 array index (EUVD-2025-19797 / Nessus ID 243500)
3 days 18 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.15.2. Affected by this issue is the function __be32 of the component openvswitch. Executing a manipulation can lead to improper validation of array index.
This vulnerability is tracked as CVE-2025-38146. The attack is only possible within the local network. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2025-38144 | Linux Kernel up to 6.15.2 watchdog devm_ioremap null pointer dereference (EUVD-2025-19799 / WID-SEC-2025-1452)
3 days 18 hours ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.15.2. The impacted element is the function devm_ioremap of the component watchdog. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-38144. The attack can only be initiated within the local network. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-38143 | Linux Kernel up to 6.15.2 backlight wled_configure null pointer dereference (EUVD-2025-19800 / Nessus ID 249177)
3 days 18 hours ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.15.2. This impacts the function wled_configure of the component backlight. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2025-38143. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-38142 | Linux Kernel up to 6.1.141/6.6.93/6.12.33/6.15.2 hwmon read_string memory corruption (EUVD-2025-19801 / Nessus ID 249177)
3 days 18 hours ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.141/6.6.93/6.12.33/6.15.2. Affected is the function read_string of the component hwmon. Such manipulation leads to memory corruption.
This vulnerability is referenced as CVE-2025-38142. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-38140 | Linux Kernel up to 6.15.2 dm_revalidate_zones nr_zones allocation of resources (EUVD-2025-19803 / Nessus ID 265934)
3 days 18 hours ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.15.2. This affects the function dm_revalidate_zones. This manipulation of the argument nr_zones causes allocation of resources.
This vulnerability is tracked as CVE-2025-38140. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-38141 | Linux Kernel up to 6.12.33/6.15.2 dm_get_live_table use after free (EUVD-2025-19802 / Nessus ID 265934)
3 days 18 hours ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.33/6.15.2. This impacts the function dm_get_live_table. Such manipulation leads to use after free.
This vulnerability is listed as CVE-2025-38141. The attack must be carried out from within the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2025-38139 | Linux Kernel up to 6.15.2 lib/iov_iter.c netfs_retry_write_stream out-of-bounds (EUVD-2025-19804 / Nessus ID 265934)
3 days 18 hours ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.15.2. The impacted element is the function netfs_retry_write_stream in the library lib/iov_iter.c. The manipulation results in out-of-bounds read.
This vulnerability is identified as CVE-2025-38139. The attack can only be performed from the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-38138 | Linux Kernel up to 6.15.2 dmaengine udma_probe null pointer dereference (EUVD-2025-19805 / Nessus ID 247771)
3 days 18 hours ago
A vulnerability described as critical has been identified in Linux Kernel up to 6.15.2. This affects the function udma_probe of the component dmaengine. The manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-38138. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-27456 | util-linux up to 2.41.3 /usr/bin/mount fork link following (GHSA-qq4x-vfq4-9h9g / Nessus ID 307050)
3 days 18 hours ago
A vulnerability marked as critical has been reported in util-linux up to 2.41.3. The impacted element is the function fork of the file /usr/bin/mount. This manipulation causes link following.
The identification of this vulnerability is CVE-2026-27456. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-39977 | flatpak -builder up to 1.4.7 g_file_resolve_relative_path path traversal (Nessus ID 307042)
3 days 18 hours ago
A vulnerability was found in flatpak -builder up to 1.4.7. It has been declared as critical. This vulnerability affects the function g_file_resolve_relative_path. Executing a manipulation can lead to path traversal.
This vulnerability is handled as CVE-2026-39977. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-23660 | Microsoft Windows Admin Center in Azure Portal access control (Nessus ID 307058)
3 days 18 hours ago
A vulnerability categorized as critical has been discovered in Microsoft Windows Admin Center in Azure Portal. This issue affects some unknown processing. The manipulation results in improper access controls.
This vulnerability is known as CVE-2026-23660. Attacking locally is a requirement. No exploit is available.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2026-32862 | NI LabVIEW up to 26.1.0 VI File Parser InitResourceMgr out-of-bounds write (Nessus ID 307060)
3 days 18 hours ago
A vulnerability marked as critical has been reported in NI LabVIEW up to 22.x/23.3.8/24.3.5/25.3.3/26.1.0. This vulnerability affects the function ResFileFactory::InitResourceMgr of the component VI File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is traded as CVE-2026-32862. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com