imPC@ndo EN

Vulnerabilità Linux

14.802 CVE

CVE-2012-3520
Bassa 1.9

The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) …

linux linux_kernel
0.00EPSS
CVE-2011-4594
Media 5.5

The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.

linux linux_kernel
0.00EPSS
CVE-2011-1747
Media 4.7

The agp subsystem in the Linux kernel 2.6.38.5 and earlier does not properly restrict memory allocation by the (1) AGPIOC_RESERVE and (2) AGPIOC_ALLOCATE ioctls, which allows local users to cause a denial of service (memory consumption) by making many calls to…

linux linux_kernel
0.00EPSS
CVE-2008-2826
Media 4.9

Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse
0.00EPSS
CVE-2022-49051
Media 6.8

In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Fix out-of-bounds accesses in RX fixup aqc111_rx_fixup() contains several out-of-bounds accesses that can be triggered by a malicious (or defective) USB device, in particul…

linux linux_kernel
0.00EPSS
CVE-2023-2236
Alta 7.8

A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a us…

linux linux_kernel · netapp hci_baseboard_management_controller
0.00EPSS
CVE-2022-1263
Media 5.5

A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of serv…

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2022-32296
Bassa 3.3

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

linux linux_kernel
0.00EPSS
CVE-2022-24959
Media 5.5

An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-17805
Alta 7.8

The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitial…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse leap · e altri 4
0.00EPSS
CVE-2016-10208
Media 4.3

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 im…

linux linux_kernel
0.00EPSS
CVE-2014-3646
Media 5.5

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse evergreen · e altri 2
0.00EPSS
CVE-2014-3182
Media 6.9

Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provid…

linux linux_kernel
0.00EPSS
CVE-2010-3067
Media 4.9

Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 4
0.00EPSS
CVE-2018-16885
Media 4.7

A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a sys…

linux linux_kernel · redhat enterprise_linux_server
0.00EPSS
CVE-2018-12930
Alta 7.8

ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted nt…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2010-4169
Media 4.9

Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.

fedoraproject fedora · linux linux_kernel · opensuse opensuse · suse linux_enterprise_desktop · e altri 2
0.00EPSS
CVE-2009-1072
Media 4.9

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 7
0.00EPSS
CVE-2008-2944
Media 4.9

Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the GNU GDB tests…

fedoraproject fedora_core · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2006-1052
Bassa 2.1

The selinux_ptrace logic in hooks.c in SELinux for Linux 2.6.6 allows local users with ptrace permissions to change the tracer SID to an SID of another process.

linux linux_kernel
0.00EPSS
CVE-2004-0138
Media 4.9

The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architecture), which triggers a BUG() when an invalid VMA is unmapped.

linux linux_kernel
0.00EPSS
CVE-2001-1392
Bassa 2.1

The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by unloading and reloading the drivers.

linux linux_kernel
0.00EPSS
CVE-2001-1393
Bassa 2.1

Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).

linux linux_kernel
0.00EPSS
CVE-2026-64091
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated by first checking the number of VLANs which have at least one TT entry. A new buffer with the correct …

linux linux_kernel
0.00EPSS
CVE-2026-53284
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: btrfs: only release the dirty pages io tree after successful writes [WARNING] With extra warning on dirty extent buffers at umount (aka, the next patch in the series), test case generic/388 …

linux linux_kernel
0.00EPSS