Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sentry launches MCP monitoring tool

      August 14, 2025

      10 Benefits of Hiring a React.js Development Company (2025–2026 Edition)

      August 13, 2025

      From Line To Layout: How Past Experiences Shape Your Design Career

      August 13, 2025

      Hire React.js Developers in the US: How to Choose the Right Team for Your Needs

      August 13, 2025

      I’ve tested every Samsung Galaxy phone in 2025 – here’s the model I’d recommend on sale

      August 14, 2025

      Google Photos just put all its best editing tools a tap away – here’s the shortcut

      August 14, 2025

      Claude can teach you how to code now, and more – how to try it

      August 14, 2025

      One of the best work laptops I’ve tested has MacBook written all over it (but it’s even better)

      August 14, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Controlling Execution Flow with Laravel’s Sleep Helper

      August 14, 2025
      Recent

      Controlling Execution Flow with Laravel’s Sleep Helper

      August 14, 2025

      Generate Secure Temporary Share Links for Files in Laravel

      August 14, 2025

      This Week in Laravel: Filament 4, Laravel Boost, and Junie Review

      August 14, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      KDE Plasma 6 on Wayland: the Payoff for Years of Plumbing

      August 14, 2025
      Recent

      KDE Plasma 6 on Wayland: the Payoff for Years of Plumbing

      August 14, 2025

      FOSS Weekly #25.33: Debian 13 Released, Torvalds vs RISC-V, Arch’s New Tool, GNOME Perfection and More Linux Stuff

      August 14, 2025

      Ultimate ChatGPT-5 Prompt Guide: 52 Ideas for Any Task

      August 14, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-31223 – Apple Safari Web Content Memory Corruption

    CVE-2025-31223 – Apple Safari Web Content Memory Corruption

    May 13, 2025

    CVE ID : CVE-2025-31223

    Published : May 12, 2025, 10:15 p.m. | 17 hours, 19 minutes ago

    Description : The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. Processing maliciously crafted web content may lead to memory corruption.

    Severity: 8.0 | HIGH

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-4649 – Centreon Web Privilege Escalation Vulnerability
    Next Article CVE-2025-24223 – Apple Safari Web Content Memory Corruption Vulnerability

    Related Posts

    Development

    CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities Catalog

    August 14, 2025
    Development

    From Banking Darling to $1B Fraud Magnet: Inside the Zelle Lawsuit 2025

    August 14, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-6029 & CVE-2025-6030: Replay Attacks Expose Vulnerabilities in KIA and Autoeastern Smart Keyless Entry Systems

    Security

    CVE-2025-53311 – Navayan Subscribe CSRF Stored XSS

    Common Vulnerabilities and Exposures (CVEs)

    Dune: Awakening (briefly) overtakes Elden Ring Nightreign days before it officially launches

    News & Updates

    CVE-2025-7061 – Intelbras InControl CSV Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    CVE-2025-38232 – Linux NFSd Race Condition Vulnerability

    July 4, 2025

    CVE ID : CVE-2025-38232

    Published : July 4, 2025, 2:15 p.m. | 4 hours, 57 minutes ago

    Description : In the Linux kernel, the following vulnerability has been resolved:

    NFSD: fix race between nfsd registration and exports_proc

    As of now nfsd calls create_proc_exports_entry() at start of init_nfsd
    and cleanup by remove_proc_entry() at last of exit_nfsd.

    Which causes kernel OOPs if there is race between below 2 operations:
    (i) exportfs -r
    (ii) mount -t nfsd none /proc/fs/nfsd

    for 5.4 kernel ARM64:

    CPU 1:
    el1_irq+0xbc/0x180
    arch_counter_get_cntvct+0x14/0x18
    running_clock+0xc/0x18
    preempt_count_add+0x88/0x110
    prep_new_page+0xb0/0x220
    get_page_from_freelist+0x2d8/0x1778
    __alloc_pages_nodemask+0x15c/0xef0
    __vmalloc_node_range+0x28c/0x478
    __vmalloc_node_flags_caller+0x8c/0xb0
    kvmalloc_node+0x88/0xe0
    nfsd_init_net+0x6c/0x108 [nfsd]
    ops_init+0x44/0x170
    register_pernet_operations+0x114/0x270
    register_pernet_subsys+0x34/0x50
    init_nfsd+0xa8/0x718 [nfsd]
    do_one_initcall+0x54/0x2e0

    CPU 2 :
    Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010

    PC is at : exports_net_open+0x50/0x68 [nfsd]

    Call trace:
    exports_net_open+0x50/0x68 [nfsd]
    exports_proc_open+0x2c/0x38 [nfsd]
    proc_reg_open+0xb8/0x198
    do_dentry_open+0x1c4/0x418
    vfs_open+0x38/0x48
    path_openat+0x28c/0xf18
    do_filp_open+0x70/0xe8
    do_sys_open+0x154/0x248

    Sometimes it crashes at exports_net_open() and sometimes cache_seq_next_rcu().

    and same is happening on latest 6.14 kernel as well:

    [ 0.000000] Linux version 6.14.0-rc5-next-20250304-dirty
    …
    [ 285.455918] Unable to handle kernel paging request at virtual address 00001f4800001f48
    …
    [ 285.464902] pc : cache_seq_next_rcu+0x78/0xa4
    …
    [ 285.469695] Call trace:
    [ 285.470083] cache_seq_next_rcu+0x78/0xa4 (P)
    [ 285.470488] seq_read+0xe0/0x11c
    [ 285.470675] proc_reg_read+0x9c/0xf0
    [ 285.470874] vfs_read+0xc4/0x2fc
    [ 285.471057] ksys_read+0x6c/0xf4
    [ 285.471231] __arm64_sys_read+0x1c/0x28
    [ 285.471428] invoke_syscall+0x44/0x100
    [ 285.471633] el0_svc_common.constprop.0+0x40/0xe0
    [ 285.471870] do_el0_svc_compat+0x1c/0x34
    [ 285.472073] el0_svc_compat+0x2c/0x80
    [ 285.472265] el0t_32_sync_handler+0x90/0x140
    [ 285.472473] el0t_32_sync+0x19c/0x1a0
    [ 285.472887] Code: f9400885 93407c23 937d7c27 11000421 (f86378a3)
    [ 285.473422] —[ end trace 0000000000000000 ]—

    It reproduced simply with below script:
    while [ 1 ]
    do
    /exportfs -r
    done &

    while [ 1 ]
    do
    insmod /nfsd.ko
    mount -t nfsd none /proc/fs/nfsd
    umount /proc/fs/nfsd
    rmmod nfsd
    done &

    So exporting interfaces to user space shall be done at last and
    cleanup at first place.

    With change there is no Kernel OOPs.

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    AMD’s Ryzen 8000HX refresh couldn’t come at a better time — Affordable gaming CPUs arrive as laptop prices rise

    AMD’s Ryzen 8000HX refresh couldn’t come at a better time — Affordable gaming CPUs arrive as laptop prices rise

    April 11, 2025

    CVE-2025-37997 – Netfilter Ipset Region Locking Vulnerability

    May 29, 2025

    Leaked: ROG Xbox Ally and Xbox Ally X pre-orders set for August, launch in October

    June 16, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.