Posts of last 24 hours
速修复
https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526780&idx=2&sn=9caf8a3656313521d7bfc27e0ebb7451
Anthropic 和 OpenAI 均表示已聘请第三方 AI 评估机构 METR 对各自的安全事件进行独立审查。
https://mp.weixin.qq.com/s?__biz=MzI2NTg4OTc5Nw==&mid=2247526780&idx=1&sn=76bdd49f4dd39b9db78c0d807d24d433
2026年,长亭以“AI+安全”产品体系为依托,帮助伙伴更快响应、更快跑通、更快拿到收益。
https://mp.weixin.qq.com/s?__biz=MzIwNDA2NDk5OQ==&mid=2651390575&idx=1&sn=800bdad1fe8529e5b9b89b7ba4f7513e
A vulnerability has been found in Linux Kernel up to 6.15-rc3 and classified as critical. This affects the function hfsc_change_class of the component net_sched. The manipulation leads to use after free.
This vulnerability is referenced as CVE-2025-37797. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/307206
A vulnerability was found in Linux Kernel up to 6.15-rc1 and classified as problematic. This impacts the function qdisc_tree_reduce_backlog of the component codel. The manipulation results in privilege escalation.
This vulnerability is identified as CVE-2025-37798. The attack can only be performed from the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/307207
A vulnerability classified as problematic has been found in Linux Kernel up to 6.6.88/6.12.25/6.14.4. Affected by this issue is the function xdp_prepare_buff of the component vmxnet3. Performing a manipulation results in uninitialized pointer.
This vulnerability is identified as CVE-2025-37799. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/307342
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.88/6.12.25/6.14.4/6.15-rc3. This affects the function dev_uevent of the component Driver Core. The manipulation results in null pointer dereference.
This vulnerability is known as CVE-2025-37800. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/307981
A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.135/6.6.88/6.12.25/6.14.4/6.15-rc2. This vulnerability affects the function spi_imx_setupxfer of the component spi. This manipulation causes null pointer dereference.
This vulnerability is handled as CVE-2025-37801. The attack can only be done within the local network. There is not any exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/307982
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.12.25/6.14.4/6.15-rc2. This issue affects the function wait_event_timeout of the component ksmbd. Such manipulation leads to missing initialization of a variable.
This vulnerability is uniquely identified as CVE-2025-37802. The attack can only be initiated within the local network. No exploit exists.
The affected component should be upgraded.
https://vuldb.com/vuln/307983
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.12.25/6.14.4/6.15-rc3/2714ffdbb79b48dda03334a01af90fb024f39047. Affected is an unknown function of the component tty. Such manipulation leads to injection.
This vulnerability is listed as CVE-2025-37814. The attack must be carried out from within the local network. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/307989