Search CVE reports


Toggle filters

1 – 10 of 33127 results

Status is adjusted based on your filters.


CVE-2025-39965

Medium priority
Needs evaluation

In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create...

146 affected packages

linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...

Package 22.04 LTS
linux Needs evaluation
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Not in release
linux-hwe-5.11 Not in release
linux-hwe-5.13 Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.19 Ignored
linux-hwe-6.2 Ignored
linux-hwe-6.5 Ignored
linux-hwe-6.8 Needs evaluation
linux-hwe-6.11 Not in release
linux-hwe-6.14 Not in release
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Needs evaluation
linux-allwinner-5.19 Ignored
linux-aws Needs evaluation
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Not in release
linux-aws-5.11 Not in release
linux-aws-5.13 Not in release
linux-aws-5.15 Not in release
linux-aws-5.19 Ignored
linux-aws-6.2 Ignored
linux-aws-6.5 Ignored
linux-aws-6.8 Needs evaluation
linux-aws-6.14 Not in release
linux-aws-hwe Not in release
linux-azure Needs evaluation
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Not in release
linux-azure-5.11 Not in release
linux-azure-5.13 Not in release
linux-azure-5.15 Not in release
linux-azure-5.19 Ignored
linux-azure-6.2 Ignored
linux-azure-6.5 Ignored
linux-azure-6.8 Needs evaluation
linux-azure-6.11 Not in release
linux-azure-6.14 Not in release
linux-azure-fde Needs evaluation
linux-azure-fde-5.15 Not in release
linux-azure-fde-5.19 Ignored
linux-azure-fde-6.2 Ignored
linux-azure-fde-6.14 Not in release
linux-azure-nvidia Not in release
linux-azure-nvidia-6.14 Not in release
linux-bluefield Not in release
linux-azure-edge Not in release
linux-fips Needs evaluation
linux-aws-fips Needs evaluation
linux-azure-fips Needs evaluation
linux-gcp-fips Needs evaluation
linux-gcp Needs evaluation
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Not in release
linux-gcp-5.11 Not in release
linux-gcp-5.13 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.19 Ignored
linux-gcp-6.2 Ignored
linux-gcp-6.5 Ignored
linux-gcp-6.8 Needs evaluation
linux-gcp-6.11 Not in release
linux-gcp-6.14 Not in release
linux-gke Needs evaluation
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Not in release
linux-gkeop Needs evaluation
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Not in release
linux-ibm Needs evaluation
linux-ibm-5.4 Not in release
linux-ibm-5.15 Not in release
linux-ibm-6.8 Needs evaluation
linux-intel-5.13 Not in release
linux-intel-iotg Needs evaluation
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-intel-iot-realtime Needs evaluation
linux-lowlatency Needs evaluation
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-5.19 Ignored
linux-lowlatency-hwe-6.2 Ignored
linux-lowlatency-hwe-6.5 Ignored
linux-lowlatency-hwe-6.8 Needs evaluation
linux-lowlatency-hwe-6.11 Not in release
linux-nvidia Needs evaluation
linux-nvidia-6.2 Ignored
linux-nvidia-6.5 Ignored
linux-nvidia-6.8 Needs evaluation
linux-nvidia-6.11 Not in release
linux-nvidia-lowlatency Not in release
linux-nvidia-tegra Needs evaluation
linux-nvidia-tegra-5.15 Not in release
linux-nvidia-tegra-igx Needs evaluation
linux-oracle Needs evaluation
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Not in release
linux-oracle-5.11 Not in release
linux-oracle-5.13 Not in release
linux-oracle-5.15 Not in release
linux-oracle-6.5 Ignored
linux-oracle-6.8 Needs evaluation
linux-oracle-6.14 Not in release
linux-oem Not in release
linux-oem-5.6 Not in release
linux-oem-5.10 Not in release
linux-oem-5.13 Not in release
linux-oem-5.14 Not in release
linux-oem-5.17 Ignored
linux-oem-6.0 Ignored
linux-oem-6.1 Ignored
linux-oem-6.5 Ignored
linux-oem-6.8 Not in release
linux-oem-6.11 Not in release
linux-oem-6.14 Not in release
linux-raspi Needs evaluation
linux-raspi2 Not in release
linux-raspi-5.4 Not in release
linux-raspi-realtime Not in release
linux-realtime Needs evaluation
linux-realtime-6.8 Needs evaluation
linux-realtime-6.14 Not in release
linux-riscv Ignored
linux-riscv-5.8 Not in release
linux-riscv-5.11 Not in release
linux-riscv-5.15 Not in release
linux-riscv-5.19 Ignored
linux-riscv-6.5 Ignored
linux-riscv-6.8 Needs evaluation
linux-riscv-6.14 Not in release
linux-starfive-5.19 Ignored
linux-starfive-6.2 Ignored
linux-starfive-6.5 Ignored
linux-xilinx-zynqmp Needs evaluation
Show all 146 packages Show less packages

CVE-2025-39964

Medium priority
Needs evaluation

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an...

146 affected packages

linux, linux-hwe, linux-hwe-5.4, linux-hwe-5.8, linux-hwe-5.11...

Package 22.04 LTS
linux Needs evaluation
linux-hwe Not in release
linux-hwe-5.4 Not in release
linux-hwe-5.8 Not in release
linux-hwe-5.11 Not in release
linux-hwe-5.13 Not in release
linux-hwe-5.15 Not in release
linux-hwe-5.19 Ignored
linux-hwe-6.2 Ignored
linux-hwe-6.5 Ignored
linux-hwe-6.8 Needs evaluation
linux-hwe-6.11 Not in release
linux-hwe-6.14 Not in release
linux-hwe-edge Not in release
linux-lts-xenial Not in release
linux-kvm Needs evaluation
linux-allwinner-5.19 Ignored
linux-aws Needs evaluation
linux-aws-5.0 Not in release
linux-aws-5.3 Not in release
linux-aws-5.4 Not in release
linux-aws-5.8 Not in release
linux-aws-5.11 Not in release
linux-aws-5.13 Not in release
linux-aws-5.15 Not in release
linux-aws-5.19 Ignored
linux-aws-6.2 Ignored
linux-aws-6.5 Ignored
linux-aws-6.8 Needs evaluation
linux-aws-6.14 Not in release
linux-aws-hwe Not in release
linux-azure Needs evaluation
linux-azure-4.15 Not in release
linux-azure-5.3 Not in release
linux-azure-5.4 Not in release
linux-azure-5.8 Not in release
linux-azure-5.11 Not in release
linux-azure-5.13 Not in release
linux-azure-5.15 Not in release
linux-azure-5.19 Ignored
linux-azure-6.2 Ignored
linux-azure-6.5 Ignored
linux-azure-6.8 Needs evaluation
linux-azure-6.11 Not in release
linux-azure-6.14 Not in release
linux-azure-fde Needs evaluation
linux-azure-fde-5.15 Not in release
linux-azure-fde-5.19 Ignored
linux-azure-fde-6.2 Ignored
linux-azure-fde-6.14 Not in release
linux-azure-nvidia Not in release
linux-azure-nvidia-6.14 Not in release
linux-bluefield Not in release
linux-azure-edge Not in release
linux-fips Needs evaluation
linux-aws-fips Needs evaluation
linux-azure-fips Needs evaluation
linux-gcp-fips Needs evaluation
linux-gcp Needs evaluation
linux-gcp-4.15 Not in release
linux-gcp-5.3 Not in release
linux-gcp-5.4 Not in release
linux-gcp-5.8 Not in release
linux-gcp-5.11 Not in release
linux-gcp-5.13 Not in release
linux-gcp-5.15 Not in release
linux-gcp-5.19 Ignored
linux-gcp-6.2 Ignored
linux-gcp-6.5 Ignored
linux-gcp-6.8 Needs evaluation
linux-gcp-6.11 Not in release
linux-gcp-6.14 Not in release
linux-gke Needs evaluation
linux-gke-4.15 Not in release
linux-gke-5.4 Not in release
linux-gke-5.15 Not in release
linux-gkeop Needs evaluation
linux-gkeop-5.4 Not in release
linux-gkeop-5.15 Not in release
linux-ibm Needs evaluation
linux-ibm-5.4 Not in release
linux-ibm-5.15 Not in release
linux-ibm-6.8 Needs evaluation
linux-intel-5.13 Not in release
linux-intel-iotg Needs evaluation
linux-intel-iotg-5.15 Not in release
linux-iot Not in release
linux-intel-iot-realtime Needs evaluation
linux-lowlatency Needs evaluation
linux-lowlatency-hwe-5.15 Not in release
linux-lowlatency-hwe-5.19 Ignored
linux-lowlatency-hwe-6.2 Ignored
linux-lowlatency-hwe-6.5 Ignored
linux-lowlatency-hwe-6.8 Needs evaluation
linux-lowlatency-hwe-6.11 Not in release
linux-nvidia Needs evaluation
linux-nvidia-6.2 Ignored
linux-nvidia-6.5 Ignored
linux-nvidia-6.8 Needs evaluation
linux-nvidia-6.11 Not in release
linux-nvidia-lowlatency Not in release
linux-nvidia-tegra Needs evaluation
linux-nvidia-tegra-5.15 Not in release
linux-nvidia-tegra-igx Needs evaluation
linux-oracle Needs evaluation
linux-oracle-5.0 Not in release
linux-oracle-5.3 Not in release
linux-oracle-5.4 Not in release
linux-oracle-5.8 Not in release
linux-oracle-5.11 Not in release
linux-oracle-5.13 Not in release
linux-oracle-5.15 Not in release
linux-oracle-6.5 Ignored
linux-oracle-6.8 Needs evaluation
linux-oracle-6.14 Not in release
linux-oem Not in release
linux-oem-5.6 Not in release
linux-oem-5.10 Not in release
linux-oem-5.13 Not in release
linux-oem-5.14 Not in release
linux-oem-5.17 Ignored
linux-oem-6.0 Ignored
linux-oem-6.1 Ignored
linux-oem-6.5 Ignored
linux-oem-6.8 Not in release
linux-oem-6.11 Not in release
linux-oem-6.14 Not in release
linux-raspi Needs evaluation
linux-raspi2 Not in release
linux-raspi-5.4 Not in release
linux-raspi-realtime Not in release
linux-realtime Needs evaluation
linux-realtime-6.8 Needs evaluation
linux-realtime-6.14 Not in release
linux-riscv Ignored
linux-riscv-5.8 Not in release
linux-riscv-5.11 Not in release
linux-riscv-5.15 Not in release
linux-riscv-5.19 Ignored
linux-riscv-6.5 Ignored
linux-riscv-6.8 Needs evaluation
linux-riscv-6.14 Not in release
linux-starfive-5.19 Ignored
linux-starfive-6.2 Ignored
linux-starfive-6.5 Ignored
linux-xilinx-zynqmp Needs evaluation
Show all 146 packages Show less packages

CVE-2025-61921

Medium priority
Needs evaluation

Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-Match` header parsing component of Sinatra, if the...

1 affected package

ruby-sinatra

Package 22.04 LTS
ruby-sinatra Needs evaluation
Show less packages

CVE-2025-61920

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose...

1 affected package

python-authlib

Package 22.04 LTS
python-authlib Needs evaluation
Show less packages

CVE-2025-61919

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: application/x-www-form-urlencoded`,...

1 affected package

ruby-rack

Package 22.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2025-61912

Medium priority
Needs evaluation

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn.escape_dn_chars() escapes \x00 incorrectly by emitting a backslash followed by a literal NUL byte instead of...

1 affected package

python-ldap

Package 22.04 LTS
python-ldap Needs evaluation
Show less packages

CVE-2025-61911

Medium priority
Needs evaluation

python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the sanitization method `ldap.filter.escape_filter_chars` can be tricked to skip escaping of special characters when...

1 affected package

python-ldap

Package 22.04 LTS
python-ldap Needs evaluation
Show less packages

CVE-2025-61780

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclosure vulnerability existed in `Rack::Sendfile` when running behind a proxy that supports `x-sendfile` headers...

1 affected package

ruby-rack

Package 22.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2025-59530

Medium priority
Needs evaluation

quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering...

1 affected package

golang-github-lucas-clemente-quic-go

Package 22.04 LTS
golang-github-lucas-clemente-quic-go Needs evaluation
Show less packages

CVE-2025-52885

Medium priority
Needs evaluation

Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in versions Poppler prior to 25.10.0 within the StructTreeRoot class. The issue...

1 affected package

poppler

Package 22.04 LTS
poppler Needs evaluation
Show less packages