A vulnerability was found in GNU Binutils 2.45. It has been classified as problematic. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing a manipulation results in out-of-bounds read.
This vulnerability is identified as CVE-2025-11081. The attack is only possible with local access. Additionally, an exploit exists.
It is suggested to install a patch to address this issue.
A vulnerability was found in GNU Binutils 2.45. It has been declared as critical. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is tracked as CVE-2025-11082. The attack is restricted to local execution. Moreover, an exploit is present.
A patch should be applied to remediate this issue.
The code maintainer replied with "[f]ixed for 2.46".
A vulnerability was found in GNU Binutils 2.45. It has been rated as critical. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2025-11083. The attack must be carried out locally. In addition, an exploit is available.
To fix this issue, it is recommended to deploy a patch.
The code maintainer replied with "[f]ixed for 2.46".
A vulnerability was found in Wireshark up to 4.2.13/4.4.9 and classified as problematic. The affected element is an unknown function of the component MONGO Dissector. Executing a manipulation can lead to infinite loop.
This vulnerability is tracked as CVE-2025-11626. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.16.10/6.17.0. Affected by this vulnerability is the function blk_mq_tag_update_depth of the component blk-mq. Performing a manipulation results in denial of service.
This vulnerability is reported as CVE-2025-39999. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.12.51/6.16.11/6.17.0 and classified as critical. The affected element is the function rtw89_core_tx_kick_off_and_wait of the file drivers/net/wireless/realtek/rtw89/core.c of the component wifi. Performing a manipulation results in use after free.
This vulnerability was named CVE-2025-40000. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.6.109/6.12.50/6.16.10/6.17.0. Affected is the function snprintf of the file /drivers/target/target_core_configfs.c of the component scsi. Such manipulation leads to unchecked return value.
This vulnerability is documented as CVE-2025-39998. The attack requires being on the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.16.10/6.17.0. This affects the function snd_usbmidi_free of the component ALSA. This manipulation causes use after free.
This vulnerability appears as CVE-2025-39997. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.6.110/6.12.51/6.16.10/6.17.0 and classified as critical. Affected by this vulnerability is the function timer_delete of the component tc358743. The manipulation leads to improper initialization.
This vulnerability is referenced as CVE-2025-39995. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
A vulnerability described as critical has been identified in Linux Kernel up to 6.6.109/6.12.50/6.16.10/6.17.0. Affected by this issue is the function cancel_delayed_work. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2025-39996. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.50/6.16.10/6.17.0. The impacted element is the function unuse_mm of the component mm. The manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2025-39992. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.110/6.12.50/6.16.10/6.17.0. This impacts the function cancel_delayed_work. This manipulation causes use after free.
This vulnerability is registered as CVE-2025-39994. The attack requires access to the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.109/6.12.50/6.16.10/6.17.0. Impacted is the function imon_disconnect of the file include/linux/usb.h of the component media. Executing a manipulation can lead to improper update of reference count.
This vulnerability is registered as CVE-2025-39993. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.15.193/6.1.154/6.6.108/6.12.49/6.16.9 and classified as critical. Affected by this issue is the function ndo_change_mtu of the component etas_es58x. The manipulation results in buffer overflow.
This vulnerability is identified as CVE-2025-39988. The attack can only be performed from the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.49/6.16.9. Impacted is the function get_helper_proto of the component bpf. Such manipulation leads to privilege escalation.
This vulnerability is uniquely identified as CVE-2025-39990. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.16.9. This impacts the function ndo_change_mtu of the component mcba_usb. Performing a manipulation results in buffer overflow.
This vulnerability was named CVE-2025-39985. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.16.9. Affected is the function ndo_change_mtu of the component hi311x. Executing a manipulation can lead to buffer overflow.
The identification of this vulnerability is CVE-2025-39987. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.16.9. It has been classified as critical. This affects the function ndo_change_mtu of the component sun4i_can. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2025-39986. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is recommended.