EN

Vulnerabilità Linux

14.802 CVE

CVE-2024-35856
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb in coredump hci_devcd_append() would free the skb on error so the caller don't have to free it again otherwise it would cause the double fr…

linux linux_kernel
0.00EPSS
CVE-2021-3506
Alta 7.1

An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a lea…

debian debian_linux · linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · e altri 8
0.00EPSS
CVE-2021-29647
Media 5.5

An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2020-25639
Media 4.4

A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.

fedoraproject fedora · linux linux_kernel · redhat enterprise_linux · redhat messaging_realtime_grid · e altri 1
0.00EPSS
CVE-2020-10773
Media 4.4

A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data.

linux linux_kernel
0.00EPSS
CVE-2019-11486
Alta 7.0

The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions.

debian debian_linux · linux linux_kernel · netapp active_iq · netapp hci_management_node · e altri 6
0.00EPSS
CVE-2017-9076
Alta 7.8

The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CV…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-9075
Alta 7.8

The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-7261
Media 5.5

The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GP…

linux linux_kernel
0.00EPSS
CVE-2014-2889
Media 4.6

Off-by-one error in the bpf_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 3.1.8, when BPF JIT is enabled, allows local users to cause a denial of service (system crash) or possibly gain privileges via a long jump after a condit…

linux linux_kernel
0.00EPSS
CVE-2013-0309
Media 4.7

arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system crash) via a crafted application.

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2013-0190
Media 4.9

The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer…

linux linux_kernel
0.00EPSS
CVE-2006-2448
Media 5.6

Linux kernel before 2.6.16.21 and 2.6.17, when running on PowerPC, does not perform certain required access_ok checks, which allows local users to read arbitrary kernel memory on 64-bit systems (signal_64.c) and cause a denial of service (crash) and possibly r…

linux linux_kernel
0.00EPSS
CVE-2025-21988
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending on the subrequest completion order), each of them would overwrite t…

linux linux_kernel
0.00EPSS
CVE-2024-47712
Alta 8.3

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix potential RCU dereference issue in wilc_parse_join_bss_param In the `wilc_parse_join_bss_param` function, the TSF field of the `ies` structure is accessed after the RCU r…

linux linux_kernel
0.00EPSS
CVE-2021-38203
Media 5.5

btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trigger allocation of new system chunks during times when there is a shortage of free space in the system space_info.

linux linux_kernel · netapp element_software · netapp hci_bootstrap_os · netapp hci_management_node · e altri 1
0.00EPSS
CVE-2017-16528
Media 6.6

sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2016-9806
Alta 7.8

Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system…

linux linux_kernel
0.00EPSS
CVE-2016-4440
Alta 7.8

arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitrary code o…

linux linux_kernel
0.00EPSS
CVE-2015-2672
Media 5.5

The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and consequently does not provide any protection against instruction faulting, which allows local users to cause a …

linux linux_kernel
0.00EPSS
CVE-2013-7348
Media 4.6

Double free vulnerability in the ioctx_alloc function in fs/aio.c in the Linux kernel before 3.12.4 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via vectors involving an error condition in the aio_set…

linux linux_kernel
0.00EPSS
CVE-2013-2894
Media 4.7

drivers/hid/hid-lenovo-tpkbd.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LENOVO_TPKBD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a cr…

linux linux_kernel
0.00EPSS
CVE-2025-39703
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: net, hsr: reject HSR frame if skb can't hold tag Receiving HSR frame with insufficient space to hold HSR tag in the skb can result in a crash (kernel BUG): [ 45.390915] skbuff: skb_under_…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2025-38437
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potential use-after-free in oplock/lease break ack If ksmbd_iov_pin_rsp return error, use-after-free can happen by accessing opinfo->state and opinfo_put and ksmbd_fd_put could ca…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2022-50062
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: bgmac: Fix a BUG triggered by wrong bytes_compl On one of our machines we got: kernel BUG at lib/dynamic_queue_limits.c:27! Internal error: Oops - BUG: 0 [#1] PREEMPT SMP ARM CPU: 0 PI…

linux linux_kernel
0.00EPSS