imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2017-2634
High 7.5

It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP connections, which could result in memory corruptions. A remote at…

linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_server · redhat enterprise_linux_server_aus · and 1 more
0.05EPSS
CVE-2023-3867
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds read in smb2_sess_setup ksmbd does not consider the case of that smb2 session setup is in compound request. If this is the second payload of the compound, OOB read i…

linux linux_kernel
0.05EPSS
CVE-2019-10220
High 8.8

Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.05EPSS
CVE-2020-14305
High 8.1

An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service…

linux linux_kernel · netapp a250_firmware · netapp aff_500f_firmware · netapp cloud_backup · and 2 more
0.05EPSS
CVE-2018-20836
High 8.1

An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.

canonical ubuntu_linux · debian debian_linux · f5 traffix_signaling_delivery_controller · linux linux_kernel · and 9 more
0.05EPSS
CVE-2023-1390
High 7.5

A remote denial of service vulnerability was found in the Linux kernel’s TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system with a U…

linux linux_kernel
0.05EPSS
CVE-2019-19050
High 7.5

A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.

broadcom fabric_operating_system · canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · and 13 more
0.05EPSS
CVE-2022-0742
Critical 9.1

Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.

linux linux_kernel · netapp a400_firmware · netapp aff_8300_firmware · netapp aff_8700_firmware · and 10 more
0.05EPSS
CVE-2018-10938
Medium 5.9

A flaw was found in the Linux kernel present since v4.0-rc1 and through v4.13-rc4. A crafted network packet sent remotely by an attacker may force the kernel to enter an infinite loop in the cipso_v4_optptr() function in net/ipv4/cipso_ipv4.c leading to a deni…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.05EPSS
CVE-2017-5897
Critical 9.8

The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.05EPSS
CVE-2009-4020
High 7.8

Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.

linux linux_kernel
0.05EPSS
CVE-2008-2136
High 7.8

Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel i…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.05EPSS
CVE-2022-47941
High 7.5

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.

linux linux_kernel
0.05EPSS
CVE-2002-0060
High 7.5

IRC connection tracking helper module in the netfilter subsystem for Linux 2.4.18-pre9 and earlier does not properly set the mask for conntrack expectations for incoming DCC connections, which could allow remote attackers to bypass intended firewall restrictio…

linux linux_kernel
0.05EPSS
CVE-2009-3547
High 7.0

Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · novell linux_desktop · and 10 more
0.05EPSS
CVE-2019-9003
High 7.5

In the Linux kernel before 4.20.5, attackers can trigger a drivers/char/ipmi/ipmi_msghandler.c use-after-free and OOPS by arranging for certain simultaneous execution of the code, as demonstrated by a "service ipmievd restart" loop.

canonical ubuntu_linux · linux linux_kernel · netapp cn1610_firmware · netapp hci_management_node · and 3 more
0.05EPSS
CVE-2014-6418
High 7.1

net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP addr…

canonical ubuntu_linux · linux linux_kernel
0.05EPSS
CVE-2005-2500
High 7.5

Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl proto…

linux linux_kernel
0.05EPSS
CVE-2006-4997
High 7.5

The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (freed point…

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux
0.05EPSS
CVE-2013-2206
Medium 5.4

The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a …

linux linux_kernel
0.05EPSS
CVE-2016-8666
High 7.5

The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by inte…

linux linux_kernel
0.05EPSS
CVE-2012-3364
Medium 5.0

Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the Linux kernel before 3.4.5 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via incoming frames with crafted l…

linux linux_kernel
0.05EPSS
CVE-2013-4125
Medium 5.4

The fib6_add_rt2node function in net/ipv6/ip6_fib.c in the IPv6 stack in the Linux kernel through 3.10.1 does not properly handle Router Advertisement (RA) messages in certain circumstances involving three routes that initially qualified for membership in an E…

linux linux_kernel
0.05EPSS
CVE-2016-4485
High 7.5

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_debuginfo · novell suse_linux_enterprise_server · and 1 more
0.05EPSS
CVE-2017-6214
High 7.5

The tcp_splice_read function in net/ipv4/tcp.c in the Linux kernel before 4.9.11 allows remote attackers to cause a denial of service (infinite loop and soft lockup) via vectors involving a TCP packet with the URG flag.

linux linux_kernel
0.05EPSS