imPC@ndo EN

Vulnerabilità Linux

14.802 CVE

CVE-2023-1989
Alta 7.0

A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. In this flaw, a call to btsdio_remove with an unfinished job, may cause a race problem leading to a UAF on hdev devices.

debian debian_linux · linux linux_kernel · netapp h300s · netapp h410c · e altri 3
0.00EPSS
CVE-2021-4095
Media 5.5

A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issu…

fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2019-19056
Media 4.7

A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, …

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 1
0.00EPSS
CVE-2019-16089
Media 4.1

An issue was discovered in the Linux kernel through 5.2.13. nbd_genl_status in drivers/block/nbd.c does not check the nla_nest_start_noflag return value.

linux linux_kernel
0.00EPSS
CVE-2017-18552
Alta 7.8

An issue was discovered in net/rds/af_rds.c in the Linux kernel before 4.11. There is an out of bounds write and read in the function rds_recv_track_latency.

linux linux_kernel
0.00EPSS
CVE-2010-5332
Media 5.6

In the Linux kernel before 2.6.37, an out of bounds array access happened in drivers/net/mlx4/port.c. When searching for a free entry in either mlx4_register_vlan() or mlx4_register_mac(), and there is no free entry, the loop terminates without updating the lo…

linux linux_kernel
0.00EPSS
CVE-2017-7477
Alta 7.0

Heap-based buffer overflow in drivers/net/macsec.c in the MACsec module in the Linux kernel through 4.10.12 allows attackers to cause a denial of service or possibly have unspecified other impact by leveraging the use of a MAX_SKB_FRAGS+1 size in conjunction w…

linux linux_kernel
0.00EPSS
CVE-2012-5517
Media 4.0

The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory…

linux linux_kernel
0.00EPSS
CVE-2011-0999
Media 4.9

mm/huge_memory.c in the Linux kernel before 2.6.38-rc5 does not prevent creation of a transparent huge page (THP) during the existence of a temporary stack for an exec system call, which allows local users to cause a denial of service (memory consumption) or p…

linux linux_kernel
0.00EPSS
CVE-2010-3877
Bassa 1.9

The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2010-4083
Bassa 1.9

The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) IPC_INFO, (2) SEM_INFO, (3) IPC_STAT…

debian debian_linux · linux linux_kernel · opensuse opensuse · suse linux_enterprise_desktop · e altri 3
0.00EPSS
CVE-2010-4075
Bassa 1.9

The uart_get_count function in drivers/serial/serial_core.c in the Linux kernel before 2.6.37-rc1 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCG…

linux linux_kernel
0.00EPSS
CVE-2010-0622
Bassa 2.1

The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecif…

linux linux_kernel
0.00EPSS
CVE-2008-2372
Media 4.9

The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly…

linux linux_kernel
0.00EPSS
CVE-2004-1144
Alta 7.2

Unknown vulnerability in the 32bit emulation code in Linux 2.4 on AMD64 systems allows local users to gain privileges.

linux linux_kernel
0.00EPSS
CVE-2024-56749
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: dlm: fix dlm_recover_members refcount on error If dlm_recover_members() fails we don't drop the references of the previous created root_list that holds and keep all rsbs alive during the rec…

linux linux_kernel
0.00EPSS
CVE-2023-26544
Alta 7.8

In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and media sector size.

linux linux_kernel
0.00EPSS
CVE-2019-12817
Alta 7.0

arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc syste…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 5
0.00EPSS
CVE-2017-18257
Media 5.5

The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and loop) via crafted use of the open and fallocate system calls with an FS_IOC_FIEMAP ioctl.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-16530
Media 6.6

The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to drivers/usb/storage/uas-detect.h and drivers/u…

linux linux_kernel
0.00EPSS
CVE-2015-8844
Media 5.5

The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the S and T bits set, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.

linux linux_kernel
0.00EPSS
CVE-2013-2546
Bassa 2.1

The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN ca…

linux linux_kernel · redhat enterprise_mrg
0.00EPSS
CVE-2010-4650
Media 4.6

Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server.

linux linux_kernel
0.00EPSS
CVE-2011-1044
Bassa 2.1

The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors that cau…

linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · redhat enterprise_linux_server · e altri 2
0.00EPSS
CVE-2026-31631
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce.

linux linux_kernel
0.00EPSS