Количество 26
Количество 26
BDU:2025-12072
Уязвимость компонента arm.c ядра операционной системы Linux, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
ROS-20260202-80-0038
Уязвимость kernel-lt
ROS-20260202-73-0041
Уязвимость kernel-lt
CVE-2025-37849
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error.
CVE-2025-37849
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error.
CVE-2025-37849
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error.
CVE-2025-37849
KVM: arm64: Tear down vGIC on failed vCPU creation
CVE-2025-37849
In the Linux kernel, the following vulnerability has been resolved: K ...
GHSA-4wfv-x2vf-68j5
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error.
ALT-PU-2025-6032
ALT-PU-2025-6032: package `kernel-image-pine` update to version 6.12.25-alt1
ALT-PU-2025-5774
ALT-PU-2025-5774: package `kernel-image-6.12` update to version 6.12.24-alt1
ALT-PU-2025-7195
ALT-PU-2025-7195: package `kernel-image-un-def` update to version 6.1.140-alt1
ALT-PU-2025-5786
ALT-PU-2025-5786: package `kernel-image-rt` update to version 6.12.24-alt1
SUSE-SU-2025:02000-1
Security update for the Linux Kernel
SUSE-SU-2025:01965-1
Security update for the Linux Kernel
ALT-PU-2025-12647
ALT-PU-2025-12647: package `kernel-image-rpi-un` update to version 6.12.49-alt1
SUSE-SU-2025:02333-1
Security update for the Linux Kernel
SUSE-SU-2025:02307-1
Security update for the Linux Kernel
SUSE-SU-2025:02254-1
Security update for the Linux Kernel
SUSE-SU-2025:01964-1
Security update for the Linux Kernel
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2025-12072 Уязвимость компонента arm.c ядра операционной системы Linux, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании | CVSS3: 6.2 | 0% Низкий | больше 1 года назад | |
ROS-20260202-80-0038 Уязвимость kernel-lt | CVSS3: 6.2 | 0% Низкий | 8 месяцев назад | |
ROS-20260202-73-0041 Уязвимость kernel-lt | CVSS3: 6.2 | 0% Низкий | 8 месяцев назад | |
CVE-2025-37849 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2025-37849 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error. | CVSS3: 7 | 0% Низкий | больше 1 года назад | |
CVE-2025-37849 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2025-37849 KVM: arm64: Tear down vGIC on failed vCPU creation | CVSS3: 8.8 | 0% Низкий | около 1 года назад | |
CVE-2025-37849 In the Linux kernel, the following vulnerability has been resolved: K ... | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-4wfv-x2vf-68j5 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
ALT-PU-2025-6032 ALT-PU-2025-6032: package `kernel-image-pine` update to version 6.12.25-alt1 | CVSS3: 7.8 | больше 1 года назад | ||
ALT-PU-2025-5774 ALT-PU-2025-5774: package `kernel-image-6.12` update to version 6.12.24-alt1 | CVSS3: 9.8 | больше 1 года назад | ||
ALT-PU-2025-7195 ALT-PU-2025-7195: package `kernel-image-un-def` update to version 6.1.140-alt1 | CVSS3: 9.8 | больше 1 года назад | ||
ALT-PU-2025-5786 ALT-PU-2025-5786: package `kernel-image-rt` update to version 6.12.24-alt1 | CVSS3: 9.8 | больше 1 года назад | ||
SUSE-SU-2025:02000-1 Security update for the Linux Kernel | больше 1 года назад | |||
SUSE-SU-2025:01965-1 Security update for the Linux Kernel | больше 1 года назад | |||
ALT-PU-2025-12647 ALT-PU-2025-12647: package `kernel-image-rpi-un` update to version 6.12.49-alt1 | CVSS3: 9.8 | 12 месяцев назад | ||
SUSE-SU-2025:02333-1 Security update for the Linux Kernel | около 1 года назад | |||
SUSE-SU-2025:02307-1 Security update for the Linux Kernel | около 1 года назад | |||
SUSE-SU-2025:02254-1 Security update for the Linux Kernel | около 1 года назад | |||
SUSE-SU-2025:01964-1 Security update for the Linux Kernel | больше 1 года назад |
Уязвимостей на страницу