<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Raspberry Pi</title>
  <link>https://cvedaily.com/pages/tags/raspberry-pi.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/raspberry-pi.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Raspberry Pi</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-45910 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45910</guid>
    <pubDate>Wed, 27 May 2026 14:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45910</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Fix race condition in QP timer handlers  I encontered the following warning:  WARNING: drivers/infiniband/sw/rxe/rxe_task.c:249 at rxe_sched_task+0x1c8/0x238 [rdma_rxe], CPU#0: swapper/0/0 ...   libsha1 [last unloaded: ip6_udp_tunnel]  CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Tainted: G         C          6.19.0-rc5-64k-v8…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43302 – In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: Se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43302</guid>
    <pubDate>Fri, 08 May 2026 14:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43302</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/v3d: Set DMA segment size to avoid debug warnings  When using V3D rendering with CONFIG_DMA_API_DEBUG enabled, the kernel occasionally reports a segment size mismatch. This is because 'max_seg_size' is not set. The kernel defaults to 64K. setting 'max_seg_size' to the maximum will prevent 'debug_dma_map_sg()' from complainin…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-131</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31494 – In the Linux kernel, the following vulnerability has been resolved:

net: macb: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31494</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31494</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31494</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: macb: use the current queue number for stats  There's a potential mismatch between the memory reserved for statistics and the amount of memory written.  gem_get_sset_count() correctly computes the number of stats based on the active queues, whereas gem_get_ethtool_stats() indiscriminately copies data using the maximum numbe…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31494">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2023-53785 – In the Linux kernel, the following vulnerability has been resolved:

mt76: mt792...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53785</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53785</guid>
    <pubDate>Tue, 09 Dec 2025 01:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2023-53785</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mt76: mt7921: don't assume adequate headroom for SDIO headers  mt7921_usb_sdio_tx_prepare_skb() calls mt7921_usb_sdio_write_txwi() and mt7921_skb_add_usb_sdio_hdr(), both of which blindly assume that adequate headroom will be available in the passed skb. This assumption typically is satisfied when the skb was allocated in the ne…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53785">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Unknown] CVE-2025-40321 – In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40321</guid>
    <pubDate>Mon, 08 Dec 2025 01:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk unknown">Unknown</span> CVE-2025-40321</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode  Currently, whenever there is a need to transmit an Action frame, the brcmfmac driver always uses the P2P vif to send the "actframe" IOVAR to firmware. The P2P interfaces were available when wpa_supplicant is managing the wlan interface.  However, the P2…</p>
  <p><strong>CVSS:</strong> N/A · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-60892 – An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS cust...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-60892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-60892</guid>
    <pubDate>Mon, 03 Nov 2025 15:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-60892</strong></p>
  <p>An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-key authentication' setting unintentionally re-adds a user's id_rsa.pub key from their local Windows machine to the authorized_keys file on the Raspberry Pi, even after the user explicitly deletes the key from the user interface. This creates an unintended attack surface, as it…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-60892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50537 – In the Linux kernel, the following vulnerability has been resolved:

firmware: r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50537</guid>
    <pubDate>Tue, 07 Oct 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50537</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  firmware: raspberrypi: fix possible memory leak in rpi_firmware_probe()  In rpi_firmware_probe(), if mbox_request_channel() fails, the 'fw' will not be freed through rpi_firmware_delete(), fix this leak by calling kfree() in the error path.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-53533 – In the Linux kernel, the following vulnerability has been resolved:

Input: rasp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53533</guid>
    <pubDate>Sat, 04 Oct 2025 16:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-53533</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Input: raspberrypi-ts - fix refcount leak in rpi_ts_probe  rpi_firmware_get() take reference, we need to release it in error paths as well. Use devm_rpi_firmware_get() helper to handling the resources. Also remove the existing rpi_firmware_put().</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-53455 – In the Linux kernel, the following vulnerability has been resolved:

drm/vc4: dr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-53455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-53455</guid>
    <pubDate>Wed, 01 Oct 2025 12:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-53455</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/vc4: drop all currently held locks if deadlock happens  If vc4_hdmi_reset_link() returns -EDEADLK, it means that a deadlock happened in the locking context. This situation should be addressed by dropping all currently held locks and block until the contended lock becomes available. Currently, vc4 is not dealing with the dead…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-53455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38450 – In the Linux kernel, the following vulnerability has been resolved:

wifi: mt76:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38450</guid>
    <pubDate>Fri, 25 Jul 2025 16:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38450</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_sta_set_decap_offload()  Add a NULL check for msta->vif before accessing its members to prevent a kernel panic in AP mode deployment. This also fix the issue reported in [1].  The crash occurs when this function is triggered before the station is fully initialized. T…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38371 – In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: Di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38371</guid>
    <pubDate>Fri, 25 Jul 2025 13:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38371</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/v3d: Disable interrupts before resetting the GPU  Currently, an interrupt can be triggered during a GPU reset, which can lead to GPU hangs and NULL pointer dereference in an interrupt context as shown in the following trace:   [  314.035040] Unable to handle kernel NULL pointer dereference at virtual address 00000000000000c0…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38189 – In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: Av...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38189</guid>
    <pubDate>Fri, 04 Jul 2025 14:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38189</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/v3d: Avoid NULL pointer dereference in `v3d_job_update_stats()`  The following kernel Oops was recently reported by Mesa CI:  [  800.139824] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000588 [  800.148619] Mem abort info: [  800.151402]   ESR = 0x0000000096000005 [  800.155141]   EC = 0x25:…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-38160 – In the Linux kernel, the following vulnerability has been resolved:

clk: bcm: r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-38160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-38160</guid>
    <pubDate>Thu, 03 Jul 2025 09:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-38160</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  clk: bcm: rpi: Add NULL check in raspberrypi_clk_register()  devm_kasprintf() returns NULL when memory allocation fails. Currently, raspberrypi_clk_register() does not check for this case, which results in a NULL pointer dereference.  Add NULL check after devm_kasprintf() to prevent this issue.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-38160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49946 – In the Linux kernel, the following vulnerability has been resolved:

clk: bcm: r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49946</guid>
    <pubDate>Wed, 18 Jun 2025 11:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49946</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  clk: bcm: rpi: Prevent out-of-bounds access  The while loop in raspberrypi_discover_clocks() relies on the assumption that the id of the last clock element is zero. Because this data comes from the Videocore firmware and it doesn't guarantuee such a behavior this could lead to out-of-bounds access. So fix this by providing a sen…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49946">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49945 – In the Linux kernel, the following vulnerability has been resolved:

hwmon: (gpi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49945</guid>
    <pubDate>Wed, 18 Jun 2025 11:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49945</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hwmon: (gpio-fan) Fix array out of bounds access  The driver does not check if the cooling state passed to gpio_fan_set_cur_state() exceeds the maximum cooling state as stored in fan_data->num_speeds. Since the cooling state is later used as an array index in set_fan_speed(), an array out of bounds access can occur. This can be…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-22011 – In the Linux kernel, the following vulnerability has been resolved:

ARM: dts: b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22011</guid>
    <pubDate>Tue, 08 Apr 2025 09:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-22011</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ARM: dts: bcm2711: Fix xHCI power-domain  During s2idle tests on the Raspberry CM4 the VPU firmware always crashes on xHCI power-domain resume:  root@raspberrypi:/sys/power# echo freeze > state [   70.724347] xhci_suspend finished [   70.727730] xhci_plat_suspend finished [   70.755624] bcm2835-power bcm2835-power: Power grafx o…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-57979 – In the Linux kernel, the following vulnerability has been resolved:

pps: Fix a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-57979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-57979</guid>
    <pubDate>Thu, 27 Feb 2025 02:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-57979</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  pps: Fix a use-after-free  On a board running ntpd and gpsd, I'm seeing a consistent use-after-free in sys_exit() from gpsd when rebooting:      pps pps1: removed     ------------[ cut here ]------------     kobject: '(null)' (00000000db4bec24): is not initialized, yet kobject_put() is being called.     WARNING: CPU: 2 PID: 440…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-57979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49540 – In the Linux kernel, the following vulnerability has been resolved:

rcu-tasks: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49540</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49540</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49540</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  rcu-tasks: Fix race in schedule and flush work  While booting secondary CPUs, cpus_read_[lock/unlock] is not keeping online cpumask stable. The transient online mask results in below calltrace.  [    0.324121] CPU1: Booted secondary processor 0x0000000001 [0x410fd083] [    0.346652] Detected PIPT I-cache on CPU2 [    0.347212] C…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49540">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49287 – In the Linux kernel, the following vulnerability has been resolved:

tpm: fix re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49287</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49287</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  tpm: fix reference counting for struct tpm_chip  The following sequence of operations results in a refcount warning:  1. Open device /dev/tpmrm. 2. Remove module tpm_tis_spi. 3. Write a TPM command to the file descriptor opened at step 1.  ------------[ cut here ]------------ WARNING: CPU: 3 PID: 1161 at lib/refcount.c:25 kobjec…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49194 – In the Linux kernel, the following vulnerability has been resolved:

net: bcmgen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49194</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49194</guid>
    <pubDate>Wed, 26 Feb 2025 07:00:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49194</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: bcmgenet: Use stronger register read/writes to assure ordering  GCC12 appears to be much smarter about its dependency tracking and is aware that the relaxed variants are just normal loads and stores and this is causing problems like:  [  210.074549] ------------[ cut here ]------------ [  210.079223] NETDEV WATCHDOG: enabcm…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49194">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-21688 – In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: As...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21688</guid>
    <pubDate>Mon, 10 Feb 2025 16:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-21688</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/v3d: Assign job pointer to NULL before signaling the fence  In commit e4b5ccd392b9 ("drm/v3d: Ensure job pointer is set to NULL after job completion"), we introduced a change to assign the job pointer to NULL after completing a job, indicating job completion.  However, this approach created a race condition between the DRM s…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-50031 – In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: St...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-50031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-50031</guid>
    <pubDate>Mon, 21 Oct 2024 20:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-50031</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/v3d: Stop the active perfmon before being destroyed  When running `kmscube` with one or more performance monitors enabled via `GALLIUM_HUD`, the following kernel panic can occur:  [   55.008324] Unable to handle kernel paging request at virtual address 00000000052004a4 [   55.008368] Mem abort info: [   55.008377]   ESR = 0x…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-50031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-49963 – In the Linux kernel, the following vulnerability has been resolved:

mailbox: bc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49963</guid>
    <pubDate>Mon, 21 Oct 2024 18:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-49963</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  mailbox: bcm2835: Fix timeout during suspend mode  During noirq suspend phase the Raspberry Pi power driver suffer of firmware property timeouts. The reason is that the IRQ of the underlying BCM2835 mailbox is disabled and rpi_firmware_property_list() will always run into a timeout [1].  Since the VideoCore side isn't consider a…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47716 – In the Linux kernel, the following vulnerability has been resolved:

ARM: 9410/1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47716</guid>
    <pubDate>Mon, 21 Oct 2024 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47716</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ARM: 9410/1: vfp: Use asm volatile in fmrx/fmxr macros  Floating point instructions in userspace can crash some arm kernels built with clang/LLD 17.0.6:      BUG: unsupported FP instruction in kernel mode     FPEXC == 0xc0000780     Internal error: Oops - undefined instruction: 0 [#1] ARM     CPU: 0 PID: 196 Comm: vfp-reproducer…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44993 – In the Linux kernel, the following vulnerability has been resolved:

drm/v3d: Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44993</guid>
    <pubDate>Wed, 04 Sep 2024 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44993</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()`  When enabling UBSAN on Raspberry Pi 5, we get the following warning:  [  387.894977] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/v3d/v3d_sched.c:320:3 [  387.903868] index 7 is out of range for type '__u32 [7]' [  387.909692] CPU: 0 PID: 1207 Comm: kworker/u16:2 Tai…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39461 – In the Linux kernel, the following vulnerability has been resolved:

clk: bcm: r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39461</guid>
    <pubDate>Tue, 25 Jun 2024 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39461</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  clk: bcm: rpi: Assign ->num before accessing ->hws  Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct clk_hw_onecell_data' with __counted_by, which informs the bounds sanitizer about the number of elements in hws, so that it can warn when hws is accessed out of…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-129</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-35932 – In the Linux kernel, the following vulnerability has been resolved:

drm/vc4: do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35932</guid>
    <pubDate>Sun, 19 May 2024 11:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-35932</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm/vc4: don't check if plane->state->fb == state->fb  Currently, when using non-blocking commits, we can see the following kernel warning:  [  110.908514] ------------[ cut here ]------------ [  110.908529] refcount_t: underflow; use-after-free. [  110.908620] WARNING: CPU: 0 PID: 1866 at lib/refcount.c:87 refcount_dec_not_one+…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-30247 – NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30247</guid>
    <pubDate>Fri, 29 Mar 2024 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-30247</strong></p>
  <p>NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi web-panel, no authentication is required. It is recommended that the NextCloudP…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-46933 – In the Linux kernel, the following vulnerability has been resolved:

usb: gadget...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-46933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-46933</guid>
    <pubDate>Tue, 27 Feb 2024 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-46933</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear.  ffs_data_clear is indirectly called from both ffs_fs_kill_sb and ffs_ep0_release, so it ends up being called twice when userland closes ep0 and then unmounts f_fs. If userland provided an eventfd along with function's USB descriptors, it ends up calling eventfd_ctx_put as…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-46933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49610 – MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49610</guid>
    <pubDate>Thu, 01 Feb 2024 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49610</strong></p>
  <p>MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-38759 – Raspberry Pi OS through 5.10 has the raspberry default password for the pi accou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38759</guid>
    <pubDate>Tue, 07 Dec 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-38759</strong></p>
  <p>Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38545 – Raspberry Pi 3 B+ and 4 B devices through 2021-08-09, in certain specific use ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38545</guid>
    <pubDate>Wed, 11 Aug 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38545</strong></p>
  <p>Raspberry Pi 3 B+ and 4 B devices through 2021-08-09, in certain specific use cases in which the device supplies power to audio-output equipment, allow remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, aka a "Glowworm" attack. We assume that the Raspberry Pi supplies power to some speakers. The power indicator LED of the Raspberry…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24572 – An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24572</guid>
    <pubDate>Mon, 24 Aug 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24572</strong></p>
  <p>An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack the underlying OS (Raspberry Pi) running this software, and execute commands on the system (including ones for uploading of files and execution of code).</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5105 – An exploitable memory corruption vulnerability exists in the Name Service Client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5105</guid>
    <pubDate>Thu, 26 Mar 2020 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5105</strong></p>
  <p>An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker can send a packet to a device running the GatewayService.exe to trigger this vulnerability. All variants of the CODESYS…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-20354 – The web application component of piSignage before 2.6.4 allows a remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20354</guid>
    <pubDate>Mon, 06 Jan 2020 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-20354</strong></p>
  <p>The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user) to download arbitrary files from the Raspberry Pi via api/settings/log?file=../ path traversal. In other words, this issue is in the player API for log download.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9012 – An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9012</guid>
    <pubDate>Thu, 15 Aug 2019 18:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9012</strong></p>
  <p>An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system:…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-9010 – An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway doe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9010</guid>
    <pubDate>Thu, 15 Aug 2019 18:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-9010</strong></p>
  <p>An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Control for emPC-A/iMX6, COD…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9013 – An issue was discovered in 3S-Smart CODESYS V3 products. The application may uti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9013</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9013</guid>
    <pubDate>Thu, 15 Aug 2019 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9013</strong></p>
  <p>An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless of the CPU type or operating system: CODESYS Control for BeagleBone, CODESYS Co…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9013">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19860 – Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19860</guid>
    <pubDate>Fri, 07 Jun 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19860</strong></p>
  <p>Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-18068 – The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18068</guid>
    <pubDate>Thu, 04 Apr 2019 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-18068</strong></p>
  <p>The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the highest privilege level in ARMv8) memory/register via inter-processor debugging. With a debug host processor A running in non-secure EL1 and a debug target processor B running in any privilege level, the debugging feature allows A to halt B and prom…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-15638 – The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15638</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15638</guid>
    <pubDate>Fri, 10 Nov 2017 02:29:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-15638</strong></p>
  <p>The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 SP2; before 3.6.312.333-3.10.1 in SLE Desktop 12 SP3 and Server 12 SP3; before 3.6_SVNr208-2.18.3.1 in SLE Server 11 SP4; before 3.6.312-5.9.1 in openSUSE Leap 42.2; and before 3.6.312.333-7.1 in openSUSE Leap 42.3 might allow remote attackers to bypass inte…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15638">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
