CVE-2023-52825
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix a race condition of vram buffer unref in svm code pran
CVSS
7.8
High
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Published: May 21, 2024 · Last modified: Aug 4, 2026 · CWE-362
0.2%EPSS · 30 days0.2%
2026-07-062026-08-03
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix a race condition of vram buffer unref in svm code prange->svm_bo unref can happen in both mmu callback and a callback after migrate to system ram. Both are async call in different tasks. Sync svm_bo unref operation to avoid random "use-after-free".
- git.kernel.orghttps://git.kernel.org/stable/c/50f35a907c4f9ed431fd3dbb8b871ef1cbb0718e
- git.kernel.orghttps://git.kernel.org/stable/c/709c348261618da7ed89d6c303e2ceb9e453ba74
- git.kernel.orghttps://git.kernel.org/stable/c/7d43cdd22cd81a2b079e864c4321b9aba4c6af34
- git.kernel.orghttps://git.kernel.org/stable/c/c772eacbd6d0845fc922af8716bb9d29ae27b8cf
- git.kernel.orghttps://git.kernel.org/stable/c/fc0210720127cc6302e6d6f3de48f49c3fcf5659
- git.kernel.orghttps://git.kernel.org/stable/c/50f35a907c4f9ed431fd3dbb8b871ef1cbb0718e
- git.kernel.orghttps://git.kernel.org/stable/c/709c348261618da7ed89d6c303e2ceb9e453ba74
- git.kernel.orghttps://git.kernel.org/stable/c/7d43cdd22cd81a2b079e864c4321b9aba4c6af34
- git.kernel.orghttps://git.kernel.org/stable/c/c772eacbd6d0845fc922af8716bb9d29ae27b8cf
- git.kernel.orghttps://git.kernel.org/stable/c/fc0210720127cc6302e6d6f3de48f49c3fcf5659
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2025-15630——
——0A race
condition exists in the cloud-based Omada device adoption process when an
attacker may be able to interact with the adoption workflow before a legitimate
device completes registration, resulting in provisioning information being
delivered to an attacker.
Successful
exploitation may allow disclosure of provisioning information intended for a
legitimate device.18hCVE-2026-441025.3 MED11.2%
——3An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.5dCVE-2026-16727—0.4%
——0Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement.
Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.4dCVE-2026-179996.5 MED3.4%
——1Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)1dCVE-2026-179937.0 HIG0.2%
——0Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)4dCVE-2026-179797.5 HIG10.5%
——3Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)4d