imPC@ndo EN

Vulnerabilità Linux

14.802 CVE

CVE-2020-35519
Alta 7.8

An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a sys…

linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · netapp h300s_firmware · e altri 7
0.00EPSS
CVE-2019-17351
Media 6.5

An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef3…

linux linux_kernel · xen xen
0.00EPSS
CVE-2018-5995
Media 5.5

The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.

linux linux_kernel
0.00EPSS
CVE-2017-13694
Media 5.5

The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memor…

linux linux_kernel
0.00EPSS
CVE-2017-2647
Alta 7.8

The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterat…

linux linux_kernel
0.00EPSS
CVE-2010-3297
Bassa 2.1

The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRC…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 3
0.00EPSS
CVE-2009-0745
Media 4.9

The ext4_group_add function in fs/ext4/resize.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not properly initialize the group descriptor during a resize (aka resize2fs) operation, which might allow local users to cause a denial …

linux linux_kernel
0.00EPSS
CVE-2009-0031
Media 4.9

Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."

linux linux_kernel
0.00EPSS
CVE-2026-64160
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i_size and ->zero_point Fix potential tearing in using ->remote_i_size and ->zero_point by copying i_size_read() and i_size_write() and using the…

linux linux_kernel
0.00EPSS
CVE-2025-21673
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS targets before it realiz…

linux linux_kernel
0.00EPSS
CVE-2025-21663
Critica 10.0

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from device tree Nvidia's Tegra MGBE controllers require the IOMMU "Stream ID" (SID) to be written to the MGBE_WRAP_AXI_ASID0_CTRL register. T…

linux linux_kernel
0.00EPSS
CVE-2023-32820
Alta 7.5

In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue …

google android · linux linux_kernel · linuxfoundation yocto · mediatek iot_yocto
0.00EPSS
CVE-2022-4696
Alta 7.8

There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter…

linux linux_kernel
0.00EPSS
CVE-2011-4916
Media 5.5

Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

linux linux_kernel
0.00EPSS
CVE-2017-8072
Alta 7.8

The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 does not have the expected EIO error status for a zero-length report, which allows local users to have an unspecified impact via unknown vectors.

linux linux_kernel
0.00EPSS
CVE-2014-9730
Media 4.9

The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.

linux linux_kernel
0.00EPSS
CVE-2012-5532
Media 4.9

The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exis…

linux linux_kernel
0.00EPSS
CVE-2011-2213
Media 4.9

The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions…

linux linux_kernel · redhat enterprise_linux_aus · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · e altri 2
0.00EPSS
CVE-2011-1013
Alta 7.2

Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users…

linux linux_kernel · openbsd openbsd
0.00EPSS
CVE-2010-3861
Bassa 2.1

The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a la…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · suse linux_enterprise_desktop · e altri 2
0.00EPSS
CVE-2010-3298
Bassa 2.1

The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT i…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 3
0.00EPSS
CVE-2010-3078
Media 5.5

The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl cal…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · suse suse_linux_enterprise_desktop · e altri 2
0.00EPSS
CVE-2006-0558
Media 4.9

perfmon (perfmon.c) in Linux kernel on IA64 architectures allows local users to cause a denial of service (crash) by interrupting a task while another process is accessing the mm_struct, which triggers a BUG_ON action in the put_page_testzero function.

linux linux_kernel
0.00EPSS
CVE-2004-0229
Media 4.6

The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.

gentoo linux · linux linux_kernel
0.00EPSS
CVE-1999-1341
Media 4.6

Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.

linux linux_kernel
0.00EPSS