Количество 28
Количество 28
BDU:2025-10752
Уязвимость функции memdup_user ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260304-80-0048
Уязвимость kernel-lt
ROS-20260304-73-0035
Уязвимость kernel-lt
CVE-2025-38257
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow. In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later. Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations. Found by Linux Verification Center (linuxtesting.org).
CVE-2025-38257
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow. In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later. Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations. Found by Linux Verification Center (linuxtesting.org).
CVE-2025-38257
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow. In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later. Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations. Found by Linux Verification Center (linuxtesting.org).
CVE-2025-38257
s390/pkey: Prevent overflow in size calculation for memdup_user()
CVE-2025-38257
In the Linux kernel, the following vulnerability has been resolved: s ...
GHSA-wgwx-65v3-j243
In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow. In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later. Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations. Found by Linux Verification Center (linuxtesting.org).
SUSE-SU-2026:0090-1
Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise 15 SP5)
ALT-PU-2025-16596
ALT-PU-2025-16596: package `kernel-image-un-def` update to version 6.1.144-alt1
SUSE-SU-2025:02588-1
Security update for the Linux Kernel
SUSE-SU-2025:02848-1
Security update for the Linux Kernel
SUSE-SU-2025:02849-1
Security update for the Linux Kernel
ALT-PU-2025-16509
ALT-PU-2025-16509: package `kernel-image-6.12` update to version 6.12.41-alt1
ALT-PU-2025-16464
ALT-PU-2025-16464: package `kernel-image-rt` update to version 6.12.41-alt1
ALT-PU-2026-1529
ALT-PU-2026-1529: package `kernel-image-pine` update to version 6.12.66-alt1
ALT-PU-2025-12647
ALT-PU-2025-12647: package `kernel-image-rpi-un` update to version 6.12.49-alt1
SUSE-SU-2025:03023-1
Security update for the Linux Kernel
SUSE-SU-2025:02996-1
Security update for the Linux Kernel
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2025-10752 Уязвимость функции memdup_user ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
ROS-20260304-80-0048 Уязвимость kernel-lt | CVSS3: 5.5 | 0% Низкий | 7 месяцев назад | |
ROS-20260304-73-0035 Уязвимость kernel-lt | CVSS3: 5.5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-38257 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow. In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later. Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations. Found by Linux Verification Center (linuxtesting.org). | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
CVE-2025-38257 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow. In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later. Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations. Found by Linux Verification Center (linuxtesting.org). | CVSS3: 6.7 | 0% Низкий | около 1 года назад | |
CVE-2025-38257 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow. In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later. Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations. Found by Linux Verification Center (linuxtesting.org). | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
CVE-2025-38257 s390/pkey: Prevent overflow in size calculation for memdup_user() | CVSS3: 5.5 | 0% Низкий | 9 месяцев назад | |
CVE-2025-38257 In the Linux kernel, the following vulnerability has been resolved: s ... | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
GHSA-wgwx-65v3-j243 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Prevent overflow in size calculation for memdup_user() Number of apqn target list entries contained in 'nr_apqns' variable is determined by userspace via an ioctl call so the result of the product in calculation of size passed to memdup_user() may overflow. In this case the actual size of the allocated area and the value describing it won't be in sync leading to various types of unpredictable behaviour later. Use a proper memdup_array_user() helper which returns an error if an overflow is detected. Note that it is different from when nr_apqns is initially zero - that case is considered valid and should be handled in subsequent pkey_handler implementations. Found by Linux Verification Center (linuxtesting.org). | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
SUSE-SU-2026:0090-1 Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise 15 SP5) | 9 месяцев назад | |||
ALT-PU-2025-16596 ALT-PU-2025-16596: package `kernel-image-un-def` update to version 6.1.144-alt1 | CVSS3: 9.3 | около 1 года назад | ||
SUSE-SU-2025:02588-1 Security update for the Linux Kernel | около 1 года назад | |||
SUSE-SU-2025:02848-1 Security update for the Linux Kernel | около 1 года назад | |||
SUSE-SU-2025:02849-1 Security update for the Linux Kernel | около 1 года назад | |||
ALT-PU-2025-16509 ALT-PU-2025-16509: package `kernel-image-6.12` update to version 6.12.41-alt1 | CVSS3: 8.8 | около 1 года назад | ||
ALT-PU-2025-16464 ALT-PU-2025-16464: package `kernel-image-rt` update to version 6.12.41-alt1 | CVSS3: 8.8 | около 1 года назад | ||
ALT-PU-2026-1529 ALT-PU-2026-1529: package `kernel-image-pine` update to version 6.12.66-alt1 | CVSS3: 9.8 | 8 месяцев назад | ||
ALT-PU-2025-12647 ALT-PU-2025-12647: package `kernel-image-rpi-un` update to version 6.12.49-alt1 | CVSS3: 9.8 | 12 месяцев назад | ||
SUSE-SU-2025:03023-1 Security update for the Linux Kernel | около 1 года назад | |||
SUSE-SU-2025:02996-1 Security update for the Linux Kernel | около 1 года назад |
Уязвимостей на страницу