CVE-2025-21924
In the Linux kernel, the following vulnerability has been resolved: net: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get
CVSS
7.8
High
EPSS
0.2%
p11
KEV
—
Exploit Today
3
0-100
Published: Apr 1, 2025 · Last modified: Jul 30, 2026 · CWE-459
0.2%EPSS · 30 days0.2%
2026-07-152026-08-12
In the Linux kernel, the following vulnerability has been resolved: net: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get_cycle returns an error During the initialization of ptp, hclge_ptp_get_cycle might return an error and returned directly without unregister clock and free it. To avoid that, call hclge_ptp_destroy_clock to unregist and free clock if hclge_ptp_get_cycle failed.
- git.kernel.orghttps://git.kernel.org/stable/c/21dba813d9821687a7f9aff576798ba21a859a32
- git.kernel.orghttps://git.kernel.org/stable/c/2c04e507f3a5c5dc6e2b9ab37d8cdedee1ef1a37
- git.kernel.orghttps://git.kernel.org/stable/c/33244e98aa9503585e585335fe2ceb4492630949
- git.kernel.orghttps://git.kernel.org/stable/c/9cfc43c0e6e6a31122b4008d763a2960c206aa2d
- git.kernel.orghttps://git.kernel.org/stable/c/b7365eab39831487a84e63a9638209b68dc54008
- git.kernel.orghttps://git.kernel.org/stable/c/b7d8d4529984e2d4a72a6d552fb886233e8e83cb
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-20712—2.1%
——1Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.19hCVE-2026-688095.5 MED28.1%
——8Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.2dCVE-2026-190194.8 MED22.9%
——7A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.19hCVE-2026-635452.4 LOW4.8%
——1Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.10dCVE-2026-673343.8 LOW10.0%
——3better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is false. Attackers can reuse deleted user session tokens to maintain authentication for up to seven days after account deletion.10dCVE-2026-424927.5 HIG39.0%
——12Xenstore, to have an up-to-date picture of the entire system, wants to
know of domains appearing and disappearing. To make this more robust, a
new XEN_DOMCTL_get_domain_state was introduced. The management of the
bitmap underlying that operation is tied into the binding of the
VIRQ_DOM_EXC virtual IRQ. Unfortunately an error path there would tear
down the bitmap even in cases when it wasn't set up. Unprivileged domains
can trigger that error path.16d