imPC@ndo IT

Linux vulnerabilities

14.802 CVE

CVE-2023-3772
Medium 5.5

A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel c…

debian debian_linux · fedoraproject fedora · linux linux_kernel · redhat enterprise_linux · and 2 more
0.00EPSS
CVE-2019-19066
Medium 4.7

A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · and 2 more
0.00EPSS
CVE-2017-15274
Medium 5.5

security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction with a nonzero length value, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted add_key or…

linux linux_kernel
0.00EPSS
CVE-2017-1000252
Medium 5.5

The KVM subsystem in the Linux kernel through 4.13.3 allows guest OS users to cause a denial of service (assertion failure, and hypervisor hang or crash) via an out-of bounds guest_irq value, related to arch/x86/kvm/vmx.c and virt/kvm/eventfd.c.

linux linux_kernel
0.00EPSS
CVE-2016-10154
Medium 5.5

The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified …

linux linux_kernel
0.00EPSS
CVE-2014-9420
Medium 4.9

The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 does not restrict the number of Rock Ridge continuation entries, which allows local users to cause a denial of service (infinite loop, and system crash or hang) via a crafted iso9…

linux linux_kernel
0.00EPSS
CVE-2013-7269
Medium 4.9

The nr_recvmsg function in net/netrom/af_netrom.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel mem…

linux linux_kernel
0.00EPSS
CVE-2013-2058
Medium 4.7

The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic …

linux linux_kernel
0.00EPSS
CVE-2013-4205
Medium 4.7

Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory consumption) via an invalid CLONE_NEWUSER unshare call.

linux linux_kernel
0.00EPSS
CVE-2013-4127
Medium 4.7

Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net.c in the Linux kernel through 3.10.3 allows local users to cause a denial of service (OOPS and system crash) via vectors involving powering on a virtual machine.

linux linux_kernel
0.00EPSS
CVE-2005-4618
Low 3.6

Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called f…

linux linux_kernel
0.00EPSS
CVE-2005-3055
Low 2.1

Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2026-43254
High 7.5

In the Linux kernel, the following vulnerability has been resolved: ovpn: tcp - fix packet extraction from stream When processing TCP stream data in ovpn_tcp_recv, we receive large cloned skbs from __strp_rcv that may contain multiple coalesced packets. The …

linux linux_kernel
0.00EPSS
CVE-2026-43164
High 7.5

In the Linux kernel, the following vulnerability has been resolved: udplite: Fix null-ptr-deref in __udp_enqueue_schedule_skb(). syzbot reported null-ptr-deref of udp_sk(sk)->udp_prod_queue. [0] Since the cited commit, udp_lib_init_sock() can fail, as can u…

linux linux_kernel
0.00EPSS
CVE-2025-38734
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF on smcsk after smc_listen_out() BPF CI testing report a UAF issue: [ 16.446633] BUG: kernel NULL pointer dereference, address: 000000000000003 0 [ 16.447134] #PF: …

linux linux_kernel
0.00EPSS
CVE-2020-12655
Medium 5.5

An issue was discovered in xfs_agf_verify in fs/xfs/libxfs/xfs_alloc.c in the Linux kernel through 5.6.10. Attackers may trigger a sync of excessive duration via an XFS v5 image with crafted metadata, aka CID-d0c7feaf8767.

linux linux_kernel
0.00EPSS
CVE-2019-19525
Medium 4.6

In the Linux kernel before 5.3.6, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/ieee802154/atusb.c driver, aka CID-7fd25e6fc035.

debian debian_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2019-19068
Medium 4.6

A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka …

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · and 2 more
0.00EPSS
CVE-2019-15030
Medium 4.4

In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional me…

canonical ubuntu_linux · linux linux_kernel · opensuse leap · redhat enterprise_linux
0.00EPSS
CVE-2019-11811
High 7.0

An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c, drivers/char/ipmi/ipmi_si_mem_io.c, and drivers/ch…

linux linux_kernel · opensuse leap · redhat enterprise_linux · redhat enterprise_linux_aus · and 5 more
0.00EPSS
CVE-2018-1068
Medium 6.7

A flaw was found in the Linux 4.x kernel's implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · redhat enterprise_linux_desktop · and 6 more
0.00EPSS
CVE-2017-17741
Medium 6.5

The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-12193
Medium 5.5

The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demon…

linux linux_kernel
0.00EPSS
CVE-2017-5548
High 7.8

drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact b…

linux linux_kernel
0.00EPSS
CVE-2016-2548
Medium 6.2

sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists after a close or stop action, which allows local users to cause a denial of service (system crash) via a crafted ioctl call, related to the (1) snd_timer_close and (2) _snd_timer_…

linux linux_kernel
0.00EPSS