Skip to main content

Threats Tagged 'cve-2025-40322'

View all threats tagged with 'cve-2025-40322'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-40322

Threats Tagged 'cve-2025-40322'

Click on any threat for detailed analysis and mitigation recommendations

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: Kernel: Privilege escalation via uninitialized data in vmci transport packet (CVE-2025-38403) * kernel: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (CVE-2026-43114) * kernel: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (CVE-2026-46099) * kernel: rxrpc: Fix potential UAF after skb_unshare() failure (CVE-2026-45998) * kernel: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (CVE-2026-46056) * kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117) * kernel: RDMA/mana: Validate rx_hash_key_len (CVE-2026-46145) * kernel: ipv6: fix possible UAF in icmpv6_rcv() (CVE-2026-53006) * kernel: ice: fix double-free of tx_buf skb (CVE-2026-53009) * kernel: USB: serial: io_ti: fix heap overflow in get_manuf_info() (CVE-2026-53196) * kernel: scsi: target: iscsi: Validate CHAP_R length before base64 decode (CVE-2026-63886) * kernel: crypto: qat - validate RSA CRT component lengths (CVE-2026-64304) Bug Fix(es) and Enhancement(s): * smb: client: use actual path when queryfs (JIRA:RHEL-145425) * RT scheduler livelock caused by missing backport of 94894c9c477e [rhel-9.4.z] (JIRA:RHEL-244408) * kernel warning : kernel/softirq.c:306 do_softirq_post_smp_call_flush+0x29/0x60 when system is booted with nosmt [rhel-9.4.z] (JIRA:RHEL-80300) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Multiple security vulnerabilities affecting the Linux kernel in Red Hat Enterprise Linux 9.6 Extended Update Support and related products have been addressed in a security update. The issues include buffer overflows, use-after-free, out-of-bounds reads and writes, and information disclosure in various kernel subsystems such as NFS, Bluetooth, RDMA, SMB client, and font glyph handling. These vulnerabilities have a moderate security impact and require a system reboot after patching to take effect.

Join the discussion

A high-severity vulnerability in the Linux kernel's framebuffer device (fbdev) bitblit code was resolved. The issue involved out-of-bounds reads caused by improper bound-checking of glyph indices in the bit_putcs_aligned() and bit_putcs_unaligned() functions. These functions derived glyph pointers from character values masked by 0xff or 0x1ff, which could exceed the actual font's glyph count, leading to reads past the end of the font array. The fix clamps the glyph index to the actual glyph count to prevent this out-of-bounds access. This vulnerability was identified and reported by syzbot. No known exploits are reported in the wild.

Join the discussion

A vulnerability in the Linux kernel's framebuffer device (fbdev) bitblit code allowed out-of-bounds reads due to improper bounds checking of glyph indices in bit_putcs_aligned() and bit_putcs_unaligned(). This flaw was fixed by clamping the glyph index to the actual glyph count, preventing reads past the end of the built-in font array. The issue was reported by syzbot and affects certain Linux kernel versions prior to specific patched releases.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:408 [inline] print_report+0xc3/0x670 mm/kasan/report.c:521 kasan_report+0xe0/0x110 mm/kasan/report.c:634 strlen+0x93/0xa0 lib/string.c:420 __fortify_strlen include/linux/fortify-string.h:268 [inline] get_kobj_path_length lib/kobject.c:118 [inline] kobject_get_path+0x3f/0x2a0 lib/kobject.c:158 kobject_uevent_env+0x289/0x1870 lib/kobject_uevent.c:545 ib_register_device drivers/infiniband/core/device.c:1472 [inline] ib_register_device+0x8cf/0xe00 drivers/infiniband/core/device.c:1393 rxe_register_device+0x275/0x320 drivers/infiniband/sw/rxe/rxe_verbs.c:1552 rxe_net_add+0x8e/0xe0 drivers/infiniband/sw/rxe/rxe_net.c:550 rxe_newlink+0x70/0x190 drivers/infiniband/sw/rxe/rxe.c:225 nldev_newlink+0x3a3/0x680 drivers/infiniband/core/nldev.c:1796 rdma_nl_rcv_msg+0x387/0x6e0 drivers/infiniband/core/netlink.c:195 rdma_nl_rcv_skb.constprop.0.isra.0+0x2e5/0x450 netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline] netlink_unicast+0x53a/0x7f0 net/netlink/af_netlink.c:1339 netlink_sendmsg+0x8d1/0xdd0 net/netlink/af_netlink.c:1883 sock_sendmsg_nosec net/socket.c:712 [inline] __sock_sendmsg net/socket.c:727 [inline] ____sys_sendmsg+0xa95/0xc70 net/socket.c:2566 ___sys_sendmsg+0x134/0x1d0 net/socket.c:2620 __sys_sendmsg+0x16d/0x220 net/socket.c:2652 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xcd/0x260 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f This problem is similar to the problem that the commit 1d6a9e7449e2 ("RDMA/core: Fix use-after-free when rename device name") fixes. The root cause is: the function ib_device_rename() renames the name with lock. But in the function kobject_uevent(), this name is accessed without lock protection at the same time. The solution is to add the lock protection when this name is accessed in the function kobject_uevent().

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cve-2025-40322
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses