Количество 26
Количество 26
BDU:2025-12276
Уязвимость компонента acpi ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании
ROS-20260121-80-0021
Уязвимость kernel-lt
ROS-20260121-73-0036
Уязвимость kernel-lt
CVE-2025-22044
In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first verifies that a user-provided value call_pkg->nd_family of type u64 is not equal to 0. Then the value is converted to int, and only after that is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while the lower 32 bits are zero. Furthermore, it is best to return EINVAL immediately upon seeing the invalid user input. The WARNING is insufficient to prevent further undefined behavior based on other invalid user input. All checks of the input value should be applied to the original variable call_pkg->nd_family. [iweiny: update commit message]
CVE-2025-22044
In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first verifies that a user-provided value call_pkg->nd_family of type u64 is not equal to 0. Then the value is converted to int, and only after that is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while the lower 32 bits are zero. Furthermore, it is best to return EINVAL immediately upon seeing the invalid user input. The WARNING is insufficient to prevent further undefined behavior based on other invalid user input. All checks of the input value should be applied to the original variable call_pkg->nd_family. [iweiny: update commit message]
CVE-2025-22044
In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first verifies that a user-provided value call_pkg->nd_family of type u64 is not equal to 0. Then the value is converted to int, and only after that is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while the lower 32 bits are zero. Furthermore, it is best to return EINVAL immediately upon seeing the invalid user input. The WARNING is insufficient to prevent further undefined behavior based on other invalid user input. All checks of the input value should be applied to the original variable call_pkg->nd_family. [iweiny: update commit message]
CVE-2025-22044
acpi: nfit: fix narrowing conversion in acpi_nfit_ctl
CVE-2025-22044
In the Linux kernel, the following vulnerability has been resolved: a ...
GHSA-65j3-jrj3-4mgp
In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first verifies that a user-provided value call_pkg->nd_family of type u64 is not equal to 0. Then the value is converted to int, and only after that is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while the lower 32 bits are zero. Furthermore, it is best to return EINVAL immediately upon seeing the invalid user input. The WARNING is insufficient to prevent further undefined behavior based on other invalid user input. All checks of the input value should be applied to the original variable call_pkg->nd_family. [iweiny: update commit message]
ALT-PU-2025-16453
ALT-PU-2025-16453: package `kernel-image-pine` update to version 6.12.23-alt2
ALT-PU-2025-6606
ALT-PU-2025-6606: package `kernel-image-rt` update to version 5.10.237-alt1.rt131
ALT-PU-2025-6382
ALT-PU-2025-6382: package `kernel-image-std-def` update to version 5.10.237-alt1
ALT-PU-2025-5774
ALT-PU-2025-5774: package `kernel-image-6.12` update to version 6.12.24-alt1
ALT-PU-2025-7195
ALT-PU-2025-7195: package `kernel-image-un-def` update to version 6.1.140-alt1
ALT-PU-2025-5786
ALT-PU-2025-5786: package `kernel-image-rt` update to version 6.12.24-alt1
SUSE-SU-2025:01972-1
Security update for the Linux Kernel
SUSE-SU-2025:01707-1
Security update for the Linux Kernel
SUSE-SU-2025:01614-1
Security update for the Linux Kernel
ALT-PU-2025-12647
ALT-PU-2025-12647: package `kernel-image-rpi-un` update to version 6.12.49-alt1
SUSE-SU-2025:01951-1
Security update for the Linux Kernel
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2025-12276 Уязвимость компонента acpi ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.5 | больше 1 года назад | ||
ROS-20260121-80-0021 Уязвимость kernel-lt | CVSS3: 5.5 | 8 месяцев назад | ||
ROS-20260121-73-0036 Уязвимость kernel-lt | CVSS3: 5.5 | 8 месяцев назад | ||
CVE-2025-22044 In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first verifies that a user-provided value call_pkg->nd_family of type u64 is not equal to 0. Then the value is converted to int, and only after that is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while the lower 32 bits are zero. Furthermore, it is best to return EINVAL immediately upon seeing the invalid user input. The WARNING is insufficient to prevent further undefined behavior based on other invalid user input. All checks of the input value should be applied to the original variable call_pkg->nd_family. [iweiny: update commit message] | CVSS3: 7.1 | больше 1 года назад | ||
CVE-2025-22044 In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first verifies that a user-provided value call_pkg->nd_family of type u64 is not equal to 0. Then the value is converted to int, and only after that is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while the lower 32 bits are zero. Furthermore, it is best to return EINVAL immediately upon seeing the invalid user input. The WARNING is insufficient to prevent further undefined behavior based on other invalid user input. All checks of the input value should be applied to the original variable call_pkg->nd_family. [iweiny: update commit message] | CVSS3: 5.5 | больше 1 года назад | ||
CVE-2025-22044 In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first verifies that a user-provided value call_pkg->nd_family of type u64 is not equal to 0. Then the value is converted to int, and only after that is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while the lower 32 bits are zero. Furthermore, it is best to return EINVAL immediately upon seeing the invalid user input. The WARNING is insufficient to prevent further undefined behavior based on other invalid user input. All checks of the input value should be applied to the original variable call_pkg->nd_family. [iweiny: update commit message] | CVSS3: 7.1 | больше 1 года назад | ||
CVE-2025-22044 acpi: nfit: fix narrowing conversion in acpi_nfit_ctl | CVSS3: 5.5 | 7 месяцев назад | ||
CVE-2025-22044 In the Linux kernel, the following vulnerability has been resolved: a ... | CVSS3: 7.1 | больше 1 года назад | ||
GHSA-65j3-jrj3-4mgp In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: fix narrowing conversion in acpi_nfit_ctl Syzkaller has reported a warning in to_nfit_bus_uuid(): "only secondary bus families can be translated". This warning is emited if the argument is equal to NVDIMM_BUS_FAMILY_NFIT == 0. Function acpi_nfit_ctl() first verifies that a user-provided value call_pkg->nd_family of type u64 is not equal to 0. Then the value is converted to int, and only after that is compared to NVDIMM_BUS_FAMILY_MAX. This can lead to passing an invalid argument to acpi_nfit_ctl(), if call_pkg->nd_family is non-zero, while the lower 32 bits are zero. Furthermore, it is best to return EINVAL immediately upon seeing the invalid user input. The WARNING is insufficient to prevent further undefined behavior based on other invalid user input. All checks of the input value should be applied to the original variable call_pkg->nd_family. [iweiny: update commit message] | CVSS3: 5.5 | больше 1 года назад | ||
ALT-PU-2025-16453 ALT-PU-2025-16453: package `kernel-image-pine` update to version 6.12.23-alt2 | CVSS3: 9.8 | больше 1 года назад | ||
ALT-PU-2025-6606 ALT-PU-2025-6606: package `kernel-image-rt` update to version 5.10.237-alt1.rt131 | CVSS3: 7.8 | больше 1 года назад | ||
ALT-PU-2025-6382 ALT-PU-2025-6382: package `kernel-image-std-def` update to version 5.10.237-alt1 | CVSS3: 7.8 | больше 1 года назад | ||
ALT-PU-2025-5774 ALT-PU-2025-5774: package `kernel-image-6.12` update to version 6.12.24-alt1 | CVSS3: 9.8 | больше 1 года назад | ||
ALT-PU-2025-7195 ALT-PU-2025-7195: package `kernel-image-un-def` update to version 6.1.140-alt1 | CVSS3: 9.8 | больше 1 года назад | ||
ALT-PU-2025-5786 ALT-PU-2025-5786: package `kernel-image-rt` update to version 6.12.24-alt1 | CVSS3: 9.8 | больше 1 года назад | ||
SUSE-SU-2025:01972-1 Security update for the Linux Kernel | больше 1 года назад | |||
SUSE-SU-2025:01707-1 Security update for the Linux Kernel | больше 1 года назад | |||
SUSE-SU-2025:01614-1 Security update for the Linux Kernel | больше 1 года назад | |||
ALT-PU-2025-12647 ALT-PU-2025-12647: package `kernel-image-rpi-un` update to version 6.12.49-alt1 | CVSS3: 9.8 | 12 месяцев назад | ||
SUSE-SU-2025:01951-1 Security update for the Linux Kernel | больше 1 года назад |
Уязвимостей на страницу