Skip to main content

CWE archive

CWE-908 CVEs

Programmatic archive

829 CVEs tagged with CWE-90891 Critical, 255 High, 450 Medium, 33 Low, 0 Unrated.

CVE-2023-53341

Published Sep 17, 2025

In the Linux kernel, the following vulnerability has been resolved: of/fdt: run soc memory setup when early_init_dt_scan_memory fails If memory has been found early_init_dt_scan…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-50374

Published Sep 17, 2025

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_{ldisc,serdev}: check percpu_init_rwsem() failure syzbot is reporting NULL pointer dereference…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-50346

Published Sep 16, 2025

In the Linux kernel, the following vulnerability has been resolved: ext4: init quota for 'old.inode' in 'ext4_rename' Syzbot found the following issue: ext4_parse_param: s_want_…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-39833

Published Sep 16, 2025

In the Linux kernel, the following vulnerability has been resolved: mISDN: hfcpci: Fix warning when deleting uninitialized timer With CONFIG_DEBUG_OBJECTS_TIMERS unloading hfcpc…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-39812

Published Sep 16, 2025

In the Linux kernel, the following vulnerability has been resolved: sctp: initialize more fields in sctp_v6_from_sk() syzbot found that sin6_scope_id was not properly initialize…

CVSS 5.5 · Medium
evidence mentions
11
Buzz score
36.4
Vendor/product tagsBeta · best-effort

CVE-2022-50335

Published Sep 15, 2025

In the Linux kernel, the following vulnerability has been resolved: 9p: set req refcount to zero to avoid uninitialized usage When a new request is allocated, the refcount will…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2022-50282

Published Sep 15, 2025

In the Linux kernel, the following vulnerability has been resolved: chardev: fix error handling in cdev_device_add() While doing fault injection test, I got the following report…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-53165

Published Sep 15, 2025

In the Linux kernel, the following vulnerability has been resolved: udf: Fix uninitialized array access for some pathnames For filenames that begin with . and are between 2 and…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-50236

Published Sep 15, 2025

In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Fix crash on isr after kexec() If the system is rebooted via isr(), the IRQ handler might be…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-39690

Published Sep 5, 2025

In the Linux kernel, the following vulnerability has been resolved: iio: accel: sca3300: fix uninitialized iio scan data Fix potential leak of uninitialized stack data to usersp…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-39684

Published Sep 5, 2025

In the Linux kernel, the following vulnerability has been resolved: comedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl() syzbot reports a KMSAN ker…

CVSS 5.5 · Medium
evidence mentions
8
Buzz score
33.5
Vendor/product tagsBeta · best-effort

CVE-2025-38737

Published Sep 5, 2025

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix smb3_init_transform_rq() to initialise buffer to NULL before…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-38718

Published Sep 4, 2025

In the Linux kernel, the following vulnerability has been resolved: sctp: linearize cloned gso packets in sctp_rcv A cloned head skb still shares these frag skbs in fraglist wit…

CVSS 7.8 · High
evidence mentions
10
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2025-38691

Published Sep 4, 2025

In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix uninited ptr deref in block/scsi layout The error occurs on the third attempt to encode extents. Wh…

CVSS 5.5 · Medium
evidence mentions
13
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2025-36893

Published Sep 4, 2025

In ReadTachyonCommands of gxp_main_actor.cc, there is a possible information leak due to uninitialized data. This could lead to local information disclosure with no additional exe…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-38658

Published Aug 22, 2025

In the Linux kernel, the following vulnerability has been resolved: nvmet: pci-epf: Do not complete commands twice if nvmet_req_init() fails Have nvmet_req_init() and req->execu…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-38644

Published Aug 22, 2025

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: reject TDLS operations when station is not associated syzbot triggered a WARN in ieee80211_td…

CVSS 5.5 · Medium
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2025-38628

Published Aug 22, 2025

In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix release of uninitialized resources on error path The commit in the fixes tag made sure that ml…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-38613

Published Aug 19, 2025

In the Linux kernel, the following vulnerability has been resolved: staging: gpib: fix unset padding field copy back to userspace The introduction of a padding field in the gpib…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-38608

Published Aug 19, 2025

In the Linux kernel, the following vulnerability has been resolved: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls When sending plaintext data, we initiall…

CVSS 8.6 · High
evidence mentions
11
Buzz score
34.9
Vendor/product tagsBeta · best-effort

CVE-2025-38579

Published Aug 19, 2025

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix KMSAN uninit-value in extent_info usage KMSAN reported a use of uninitialized value in `__is_extent…

CVSS 7.8 · High
evidence mentions
8
Buzz score
32.0
Vendor/product tagsBeta · best-effort

CVE-2025-38574

Published Aug 19, 2025

In the Linux kernel, the following vulnerability has been resolved: pptp: ensure minimal skb length in pptp_xmit() Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb dat…

CVSS 8.6 · High
evidence mentions
11
Buzz score
34.9
Vendor/product tagsBeta · best-effort

CVE-2025-38531

Published Aug 16, 2025

In the Linux kernel, the following vulnerability has been resolved: iio: common: st_sensors: Fix use of uninitialize device structs Throughout the various probe functions &indio…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-55198

Published Aug 14, 2025

Helm is a package manager for Charts for Kubernetes. Prior to version 3.18.5, when parsing Chart.yaml and index.yaml files, an improper validation of type error can lead to a pani…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 151-175 of 829 CVEsPage 7 of 34