-
CVE-2025-21983: While kvfree_rcu() itself is not fundamentally flawed, Linux now been resolved by using a more appropriate workqueue. (2nd Apr 2025)
Preface: The buddy allocator is a well-known memory management algorithm used in the Linux kernel. It is designed to efficiently allocate and deallocate memory in contiguous blocks. Background: What is RCU usage in the Linux kernel? Read-copy update (RCU) is a scalable high-performance synchronization mechanism implemented in the Linux kernel. RCU’s novel properties include support…
-
CVE-2025-2953: Floating point exception in torch[.]mkldnn_max_pool2d (31st Mar 2025)
Preface: The torch[.]nn[.]MaxPool2d function in PyTorch is used to apply a 2D max pooling operation over an input signal, which is typically an image or a batch of images. Background: A floating point exception crash when using torch[.]mkldnn_max_pool2d can occur due to several reasons, often related to invalid or extreme values for parameters like kernel…
-
Similar to previously disclosed side-channel attacks. Manufacturer (AMD) response to researcher (30-03-2025)
Preface: On 24th Oct, 2024, Researchers from Azure® Research, Microsoft® have provided to AMD a paper titled “Principled Microarchitectural Isolation on Cloud CPUs.” In their paper, the researchers describe a potential side-channel vulnerability on AMD CPUs. AMD believes that existing mitigation recommendations for prime and probe side-channel attacks remain applicable to the presented vulnerability. Background:…
-
CVE-2025-30217: SQL injection on Frappe web application framework (27th Mar 2025)
Preface: The Frappe Framework comes equipped with a wide range of built-in tools and features that accelerate the development process. Developers can leverage ready-to-use modules, templates, and components to create applications quickly. Background: Frappe Framework – A full-stack web application framework written in Python and Javascript. The framework provides a robust foundation for building web…
-
CVE-2025-30219: About RabbitMQ (26th Mar 2025)
Preface: Message queues are quite important in machine learning for several reasons: Background: RabbitMQ can be quite helpful in AI applications! RabbitMQ is an open-source message broker that facilitates communication between different parts of a system asynchronously. Here are some ways it can assist AI: If you enable the management Plugin, you will be able…
-
CVE-2025-24514: Security Focus of K8s (Kubernetes) 24th Mar 2025
Preface: A Kubernetes (K8s) sidecar controller is a custom controller designed to manage sidecar containers within a Kubernetes Pod. Sidecar containers are secondary containers that run alongside the main application container in the same Pod. They provide additional functionalities such as logging, monitoring, security, or data synchronization without altering the primary application code. Background: Ingress…
-
CVE-2024-53025: Transient DOS can occur while processing UCI command (24-03-2025)
NVD Published Date: 03/03/2025NVD Last Modified: 03/06/2025 Preface: The OpenWrt Project is a Linux operating system targeting embedded devices. Instead of trying to create a single, static firmware, OpenWrt provides a fully writable filesystem with package management. This frees you from the application selection and configuration provided by the vendor and allows you to customize…
-
CVE-2025-30472: Corosync Stack buffer overflow (23rd Mar 2025)
Preface: Even with the popularity of IP phone SIP trunking, the public telephone network still relies on PABX (Private Automatic Branch Exchange) systems in many cases. SIP trunking allows businesses to connect their IP PBX systems to the Public Switched Telephone Network (PSTN) using the Session Initiation Protocol (SIP), which facilitates voice and data communication…
-
CVE-2025-24201: iOS, iPadOS, and macOS – WebKit Out-of-Bounds Write Vulnerability Security updates (20-03-2025)
NVD Published Date: 03/11/2025NVD Last Modified: 03/14/2025 Preface: WebKit is a web browser engine used by Safari and other applications across various platforms like macOS, iOS, Linux, and Windows. It processes web content, including JavaScript, HTML, and CSS. Background: The Web Content sandbox is a security feature within WebKit that isolates web content from the…
-
CVE-2025-29909: CryptoLib’s design weakness (19-03-2025)
Preface: Human being life average 80 year old. Explorering space is a long time travel. So, it only relies on machine. Even though exploring machine can relies on solar energy. In space there is a lot of uncertainty. For example, the shock of meteorite. Furthemore, the spacecraft operates in a unique environment, the spacecraft’s power…