EN

Vulnerabilità Linux

14.802 CVE

CVE-2003-0643
Bassa 2.1

Integer signedness error in the Linux Socket Filter implementation (filter.c) in Linux 2.4.3-pre3 to 2.4.22-pre10 allows attackers to cause a denial of service (crash).

linux linux_kernel
0.00EPSS
CVE-2023-53360
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: Rework scratch handling for READ_PLUS (again) I found that the read code might send multiple requests using the same nfs_pgio_header, but nfs4_proc_read_setup() is only called once.…

linux linux_kernel
0.00EPSS
CVE-2025-21805
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the rnbd: list_add corruption. prev->next should be next (ffff88800b13e480), but was…

linux linux_kernel
0.00EPSS
CVE-2021-3501
Alta 7.1

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this v…

fedoraproject fedora · linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · e altri 15
0.00EPSS
CVE-2020-28915
Media 5.8

A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.

linux linux_kernel
0.00EPSS
CVE-2017-1000111
Alta 7.8

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. T…

debian debian_linux · linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_desktop · e altri 5
0.00EPSS
CVE-2017-6353
Media 5.5

net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. …

linux linux_kernel
0.00EPSS
CVE-2016-5400
Media 4.3

Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR …

linux linux_kernel
0.00EPSS
CVE-2016-2383
Media 5.5

The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading…

canonical ubuntu_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2014-7843
Media 4.9

The __clear_user function in arch/arm64/lib/clear_user.S in the Linux kernel before 3.17.4 on the ARM64 platform allows local users to cause a denial of service (system crash) by reading one byte beyond a /dev/zero page boundary.

linux linux_kernel
0.00EPSS
CVE-2014-7842
Media 4.9

Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation e…

linux linux_kernel
0.00EPSS
CVE-2014-8086
Media 4.7

Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT fla…

linux linux_kernel · suse suse_linux_enterprise_server
0.00EPSS
CVE-2022-47946
Media 5.5

An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. finish_wait can be skipped. An attack can occur in some situation…

linux linux_kernel
0.00EPSS
CVE-2019-19058
Media 4.7

A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2017-14051
Media 4.4

An integer overflow in the qla2x00_sysfs_write_optrom_ctl function in drivers/scsi/qla2xxx/qla_attr.c in the Linux kernel through 4.12.10 allows local users to cause a denial of service (memory corruption and system crash) by leveraging root access.

linux linux_kernel
0.00EPSS
CVE-2017-11472
Alta 7.1

The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR …

linux linux_kernel
0.00EPSS
CVE-2017-8831
Media 6.4

The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequence-num…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2005-0179
Bassa 2.1

Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.

linux linux_kernel
0.00EPSS
CVE-2002-1319
Bassa 2.1

The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.

linux linux_kernel · trustix secure_linux
0.00EPSS
CVE-2022-50363
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: skmsg: pass gfp argument to alloc_sk_msg() syzbot found that alloc_sk_msg() could be called from a non sleepable context. sk_psock_verdict_recv() uses rcu_read_lock() protection. We need th…

linux linux_kernel
0.00EPSS
CVE-2025-37749
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: net: ppp: Add bound checking for skb data on ppp_sync_txmung Ensure we have enough data in linear buffer from skb before accessing initial bytes. This prevents potential out-of-bounds access…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2025-21725
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to unset link speed It isn't guaranteed that NETWORK_INTERFACE_INFO::LinkSpeed will always be set by the server, so the client must handle any values and then preve…

linux linux_kernel
0.00EPSS
CVE-2024-56656
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips The 5760X (P7) chip's HW GRO/LRO interface is very similar to that of the previous generation (5750X or P5). However, the agg…

linux linux_kernel
0.00EPSS
CVE-2024-35969
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr Although ipv6_get_ifaddr walks inet6_addr_lst under the RCU lock, it still means hlist_for_each_entry_rcu can return an ite…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-26605
Alta 7.8

In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid.

linux linux_kernel
0.00EPSS