Posts of last 24 hours
A vulnerability was found in Linux Kernel up to 6.12.24/6.14.3/6.15-rc2. It has been rated as critical. The impacted element is the function tx_prod of the component eth. This manipulation causes denial of service.
This vulnerability is handled as CVE-2025-37873. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/308162
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.1.135/6.6.88/6.12.25/6.14.4. This affects the function p9_client_write. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2025-37879. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/308163
A vulnerability was found in Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2 and classified as critical. The impacted element is the function kvm_arch_vcpu_create. The manipulation results in use after free.
This vulnerability is reported as CVE-2025-37849. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/308173
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.12.23/6.13.11/6.14.2. This affects the function io_admin_reset_sync of the component scsi. The manipulation results in allocation of resources.
This vulnerability was named CVE-2025-37861. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
https://vuldb.com/vuln/308179
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2. Impacted is the function reset_domain. Performing a manipulation results in use after free.
This vulnerability is identified as CVE-2025-37854. The attack can only be performed from the local network. There is not any exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/308182
A vulnerability was found in Linux Kernel up to 6.12.23/6.13.11/6.14.2 and classified as critical. Affected is the function list_del of the component btrfs. Such manipulation leads to improper update of reference count.
This vulnerability is documented as CVE-2025-37856. The attack requires being on the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/308187
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.24/6.14.3/6.15-rc1. This vulnerability affects the function xe_migrate_clear. The manipulation results in use after free.
This vulnerability is known as CVE-2025-37869. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/308191
近日,国家网信办、公安部联合公布《小型个人信息处理者个人信息保护简化措施规定》(以下简称《规定》),将于2026年9月1日起施行。这一新规的出台,既是对个人信息保护法的细化落实,也是针对小型个人信息处理者合规痛点开出的精准“药方”。
https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265227&idx=5&sn=4ac4bcfcf129eb7ede63187003150dda
在律师从业人数增长缓慢、人力成本居高不下的背景下,AI正成为降本增效的利器。虽然AI目前还难以处理复杂案件,但在类案检索、合同审查、诉状起草、证据阅卷等标准化、事务性工作中,已经展现出比初级律师更快、更准的优势。
https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265227&idx=4&sn=029f649afd1fa2ef7490c9a95ee65614
近期,中国消费者协会陆续收到消费者反映,通过微信群、企业微信客服等私域渠道接收到大量医药广告。这类广告以医疗从业人员为代言人作推荐、证明,宣称产品具备疾病治疗或预防功能,引发消费者对自身健康状况不必要的担忧和恐惧。
https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265227&idx=3&sn=ec05cbb2c7cea2713f38efcabf0835cb