May

Security Update News

Update Information

Title May
Update ID AVLEONOV:9794ACDABE0763885A55DF3E6C9BB96D
Type avleonov
Published 2025-05-23T21:25:44
Last Updated 2025-05-23T21:25:44

Security Impact

CVSS Score 6.9
Severity MEDIUM
Attack Vector NETWORK

Affected CVEs

  • CVE-2020-13756
  • CVE-2023-53033
  • CVE-2024-12905
  • CVE-2024-23651
  • CVE-2024-23652
  • CVE-2025-1974
  • CVE-2025-27533
  • CVE-2025-30349
  • CVE-2025-32414
  • CVE-2025-32433
  • CVE-2025-43929
  • CVE-2025-4664

Update Details

![May ](https://avleonov.com/wp-content/uploads/2025/05/photo_825@24-05-2025_00-25-44.jpg)

**May**Linux Patch Wednesday. This time: 1091 vulnerabilities. Of those, 716 are in the Linux Kernel. ![🀯](https://s.w.org/images/core/emoji/15.1.0/72×72/1f92f.png) 5 vulnerabilities are exploited in the wild:

![πŸ”»](https://s.w.org/images/core/emoji/15.1.0/72×72/1f53b.png) **RCE** – PHP CSS Parser (CVE-2020-13756). In AttackerKB, an exploit exists.
**![πŸ”»](https://s.w.org/images/core/emoji/15.1.0/72×72/1f53b.png)DoS** – Apache ActiveMQ (CVE-2025-27533). In AttackerKB, an exploit exists.
![πŸ”»](https://s.w.org/images/core/emoji/15.1.0/72×72/1f53b.png) **SFB** – Chromium (CVE-2025-4664). In CISA KEV.
![πŸ”»](https://s.w.org/images/core/emoji/15.1.0/72×72/1f53b.png) **PathTrav** – buildkit (CVE-2024-23652) and **MemCor** – buildkit (CVE-2024-23651). In BDU FSTEC.

For 52 (![❗](https://s.w.org/images/core/emoji/15.1.0/72×72/2757.png)) more, there are signs of existing public exploits. Two trending vulnerabilities I’ve mentioned before::

![πŸ”Έ](https://s.w.org/images/core/emoji/15.1.0/72×72/1f538.png) **RCE** – Kubernetes “IngressNightmare” (CVE-2025-1974 and 4 others)
![πŸ”Έ](https://s.w.org/images/core/emoji/15.1.0/72×72/1f538.png) **RCE** – Erlang/OTP (CVE-2025-32433)

Exploits for these are also notable:

![πŸ”Έ](https://s.w.org/images/core/emoji/15.1.0/72×72/1f538.png) **EoP** – Linux Kernel (CVE-2023-53033)
![πŸ”Έ](https://s.w.org/images/core/emoji/15.1.0/72×72/1f538.png) **XSS** – Horde IMP (CVE-2025-30349)
![πŸ”Έ](https://s.w.org/images/core/emoji/15.1.0/72×72/1f538.png) **PathTrav** – tar-fs (CVE-2024-12905)
![πŸ”Έ](https://s.w.org/images/core/emoji/15.1.0/72×72/1f538.png) **SFB** – kitty (CVE-2025-43929)
![πŸ”Έ](https://s.w.org/images/core/emoji/15.1.0/72×72/1f538.png) **DoS** – libxml2 (CVE-2025-32414)

![πŸ—’](https://s.w.org/images/core/emoji/15.1.0/72×72/1f5d2.png) Full Vulristics report

На русском

View Advisory Details

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.