Weekly digest
Week 5, 2025 (27 Jan – 2 Feb)
16 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 7 high, 50% of the total. No new KEV entries. linux was the most-affected vendor with 6.
New this week, ranked by depth score
The 12 that matter most of the 16 published.
CVE-2025-21673Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS t…
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS t…
CVE-2024-13484High· 8.2A flaw was found in openshift-gitops-operator-container
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can ha…
CVE-2025-21678High· 7.8In the Linux kernel, the following vulnerability has been resolved: gtp: Destroy device along with udp socket's netns dismantle. gtp_newlink() links the device to a list in dev_net(dev) instead of src_net, where a udp tunnel socket is …
In the Linux kernel, the following vulnerability has been resolved: gtp: Destroy device along with udp socket's netns dismantle. gtp_newlink() links the device to a list in dev_net(dev) instead of src_net, where a udp tunnel socket is …
CVE-2025-21677High· 7.8In the Linux kernel, the following vulnerability has been resolved: pfcp: Destroy device along with udp socket's netns dismantle. pfcp_newlink() links the device to a list in dev_net(dev) instead of net, where a udp tunnel socket is cr…
In the Linux kernel, the following vulnerability has been resolved: pfcp: Destroy device along with udp socket's netns dismantle. pfcp_newlink() links the device to a list in dev_net(dev) instead of net, where a udp tunnel socket is cr…
CVE-2025-21669High· 7.8In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been de-assigned or assigned to another transport, we must discard any packets received becaus…
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been de-assigned or assigned to another transport, we must discard any packets received becaus…
CVE-2025-24357High· 7.5vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator
CVE-2025-24793High· 7.0snowflake-connector-python vulnerable to SQL Injection in write_pandas
snowflake-connector-python vulnerable to SQL Injection in write_pandas
CVE-2024-45339High· 7.1Insecure Temporary File usage in github.com/golang/glog
Insecure Temporary File usage in github.com/golang/glog
GHSA-274v-mgcv-cm8jMedium· 6.8Argo CD GitOps Engine does not scrub secret values from patch errors
Argo CD GitOps Engine does not scrub secret values from patch errors
CVE-2025-23216Medium· 6.8Argo CD does not scrub secret values from patch errors
Argo CD does not scrub secret values from patch errors
CVE-2025-24794Medium· 6.7snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache
CVE-2025-23367Medium· 6.5A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can sus…
Most-affected vendors
By CVEs published in the period.