NVD disclosure day

Published threat advisories for December 30, 2025

CVE advisoryCRITICAL

CVE-2025-66848

JD Cloud NAS Router Unauthorized Remote Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

JD Cloud NAS routers are affected by an unauthorized remote command execution vulnerability. Attackers can exploit this critical flaw to gain unauthorized control of the devices over the internet, potentially impacting confidentiality, integrity, and availability.

CVE advisoryCRITICAL

CVE-2023-54292

Linux Kernel RDMA Data Race Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A data race in the Linux kernel's RDMA/irdma driver could lead to system instability. This occurs due to unlocked memory access during concurrent operations, potentially impacting system stability or causing crashes if the vulnerability is reachable or relevant in your environment.

CVE advisoryCRITICAL

CVE-2023-54280

Linux Kernel CIFS Use-After-Free in Tree Connect.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's file-sharing component could allow disruption or unauthorized access to information. The issue involves a race condition during the handling of network connections for inter-process communication. This affects a core part of the operating system, potentially leading to system insta

CVE advisoryCRITICAL

CVE-2023-54258

Linux Kernel CIFS Race Condition Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's CIFS client could cause a system crash due to a race condition during file operations. This occurs when file closes conflict with oplock breaks, potentially affecting system stability. It is important to verify if Linux systems using the CIFS client are affected.

CVE advisoryCRITICAL

CVE-2023-54257

Linux Kernel macb Memory Corruption Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability exists in the Linux kernel's networking component, specifically the macb driver, when using extended buffer descriptor mode. This could lead to network and storage failures on affected devices. The issue has been resolved, and its relevance depends on whether the affected component is

CVE advisoryCRITICAL

CVE-2023-54223

Linux Kernel mlx5e XSK Invalid Buffer Access

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in the Linux kernel's mlx5e network driver that can cause a system crash due to an invalid buffer access. This occurs when using XDP sockets in receive mode on legacy request queues, where a buffer may be released twice. This issue impacts system stability and data integrity when the specific net

CVE advisoryCRITICAL

CVE-2023-54203

Linux Kernel ksmbd Slab Out-of-Bounds Write Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability exists in the Linux kernel's SMB handling where processing older SMB version 1 requests as SMB version 2 operations can lead to memory corruption. This could potentially cause system instability or denial of service if reachable. Readers should care because this issue affects core kernel functionality r

CVE advisoryCRITICAL

CVE-2023-54184

Linux Kernel iSCSI Target Use-After-Free Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Linux kernel's iSCSI target subsystem could allow for system instability or elevated privileges. This issue arises from improper handling of commands during session closure, leading to a use-after-free condition. Confirmation is needed on whether this subsystem is in use and exposed, as its exter