A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.17-rc4. This issue affects the function alloc_skb. The manipulation of the argument new_skb results in memory leak.
This vulnerability is reported as CVE-2025-39847. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.17-rc4. The affected element is the function list_first_entry of the component i40e. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2025-39853. Access to the local network is required for this attack to succeed. There is no exploit available.
The affected component should be upgraded.
A vulnerability was found in Linux Kernel up to 6.0.6. It has been declared as critical. This issue affects the function i2sbus_add_dev of the component ALSA. Such manipulation leads to memory leak.
This vulnerability is listed as CVE-2022-50431. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.0.6. The impacted element is the function kernfs_remove_by_name_ns. The manipulation leads to use after free.
This vulnerability is documented as CVE-2022-50432. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.0.3 and classified as critical. Impacted is the function kfree of the component efi. Such manipulation leads to use after free.
This vulnerability is referenced as CVE-2022-50433. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.0.18/6.1.4. Affected by this issue is the function cancel_delayed_work_sync. Executing a manipulation can lead to null pointer dereference.
This vulnerability is handled as CVE-2022-50441. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability has been found in Linux Kernel up to 6.0.6 and classified as critical. This impacts the function snd_ac97_dev_register of the component ALSA. Performing a manipulation results in memory leak.
This vulnerability is identified as CVE-2022-50427. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability classified as critical has been found in Linux Kernel up to 5.15.86/6.0.17/6.1.3. Impacted is the function ext4_fc_reserve_space. The manipulation leads to uninitialized pointer.
This vulnerability is uniquely identified as CVE-2022-50428. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.152/6.6.106/6.12.47/6.16.7. Impacted is the function bam_dma of the component dmaengine. The manipulation results in state issue.
This vulnerability is identified as CVE-2025-39923. The attack can only be performed from the local network. There is not any exploit available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.17-rc4. The affected element is the function __iodyn_find_io_region of the component pcmcia. Performing a manipulation results in null pointer dereference.
This vulnerability was named CVE-2025-39846. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.17-rc4 and classified as critical. Affected is the function ax25_kiss_rcv of the component ax25. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2025-39848. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.150/6.6.104/6.12.45/6.16.5/6.17-rc4. Impacted is the function __cfg80211_connect_result of the component wifi. This manipulation causes memory corruption.
This vulnerability appears as CVE-2025-39849. The attacker needs to be present on the local network. There is no available exploit.
You should upgrade the affected component.
The extension in the $1.2 trillion funding deal is the latest short-term solution in a monthslong saga for CISA 2015, which provides liability protections to encourage private companies to share digital threat information with the federal government.
NETSCOUT’s Arbor Threat Mitigation System (TMS) was honored with five badges, while Arbor Sightline earned one badge on G2 for the winter 2026 quarter. These badges span multiple categories. Arbor TMS was awarded badges in the following categories for winter 2026: Leader – Enterprise DDoS Protection Momentum Leader –...
Hackers are targeting Afghan government employees with phishing emails disguised as official correspondence from the office of the country’s prime minister, researchers found.
The new EU-funded GCVE project is breaking dependence on US databases to track software flaws. Discover how this decentralised system aims to ensure global cybersecurity.