imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2024-26581
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval e…

debian debian_linux · linux linux_kernel
0.02EPSS
CVE-2005-0176
Media 5.0

The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.

linux linux_kernel
0.02EPSS
CVE-2016-8440
Critica 9.8

Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call may result in hypervisor memory overwrite. Product: Android. Versions: Kernel 3.18. Android ID: A-31625306. References: QC-CR#1036747.

linux linux_kernel
0.02EPSS
CVE-2020-36158
Alta 8.8

mwifiex_cmd_802_11_ad_hoc_start in drivers/net/wireless/marvell/mwifiex/join.c in the Linux kernel through 5.10.4 might allow remote attackers to execute arbitrary code via a long SSID value, aka CID-5c455c5ab332.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp cloud_backup · e altri 1
0.02EPSS
CVE-2010-4347
Media 6.9

The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init functi…

linux linux_kernel · opensuse opensuse · suse linux_enterprise_real_time_extension
0.02EPSS
CVE-2006-3626
Media 6.2

Race condition in Linux kernel 2.6.17.4 and earlier allows local users to gain root privileges by using prctl with PR_SET_DUMPABLE in a way that causes /proc/self/environ to become setuid root.

linux linux_kernel
0.02EPSS
CVE-2011-4348
Alta 7.1

Race condition in the sctp_rcv function in net/sctp/input.c in the Linux kernel before 2.6.29 allows remote attackers to cause a denial of service (system hang) via SCTP packets. NOTE: in some environments, this issue exists because of an incomplete fix for C…

linux linux_kernel
0.02EPSS
CVE-2018-13094
Media 5.5

An issue was discovered in fs/xfs/libxfs/xfs_attr_leaf.c in the Linux kernel through 4.17.3. An OOPS may occur for a corrupted xfs image after xfs_da_shrink_inode() is called with a NULL bp.

canonical ubuntu_linux · linux linux_kernel
0.02EPSS
CVE-2023-6200
Alta 7.5

A race condition was found in the Linux Kernel. Under certain conditions, an unauthenticated attacker from an adjacent network could send an ICMPv6 router advertisement packet, causing arbitrary code execution.

linux linux_kernel
0.02EPSS
CVE-2018-14616
Media 5.5

An issue was discovered in the Linux kernel through 4.17.10. There is a NULL pointer dereference in fscrypt_do_page_crypto() in fs/crypto/crypto.c when operating on a file in a corrupted f2fs image.

linux linux_kernel
0.02EPSS
CVE-2016-10318
Media 6.5

A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user…

linux linux_kernel
0.02EPSS
CVE-2016-7913
Alta 7.8

The xc2028_set_config function in drivers/media/tuners/tuner-xc2028.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) via vectors involving omission of the firmware name from a certain data str…

canonical ubuntu_linux · linux linux_kernel
0.02EPSS
CVE-2022-27223
Alta 8.8

In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access.

debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · netapp h300e_firmware · e altri 6
0.02EPSS
CVE-2017-16939
Alta 7.8

The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPO…

debian debian_linux · linux linux_kernel
0.02EPSS
CVE-2011-1768
Media 5.4

The tunnels implementation in the Linux kernel before 2.6.34, when tunnel functionality is configured as a module, allows remote attackers to cause a denial of service (OOPS) by sending a packet during module loading.

linux linux_kernel
0.02EPSS
CVE-2019-19448
Alta 7.8

In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in try_merge_free_space in fs/btrfs/free-space-cache.c because the pointer to a left…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp a700s_firmware · e altri 14
0.02EPSS
CVE-2008-4210
Media 4.6

fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified othe…

linux linux_kernel
0.02EPSS
CVE-2017-0332
Alta 7.0

An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. …

linux linux_kernel
0.02EPSS
CVE-2019-19813
Media 5.5

In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 9
0.02EPSS
CVE-2016-9313
Alta 7.8

security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly ha…

linux linux_kernel
0.02EPSS
CVE-2016-7912
Alta 7.8

Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux kernel before 4.5.3 allows local users to gain privileges by accessing an I/O data structure after a certain callback call.

linux linux_kernel
0.02EPSS
CVE-2017-0329
Alta 7.0

An elevation of privilege vulnerability in the NVIDIA boot and power management processor driver could enable a local malicious application to execute arbitrary code within the context of the boot and power management processor. This issue is rated as High bec…

linux linux_kernel
0.02EPSS
CVE-2017-0432
Alta 7.0

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ…

linux linux_kernel
0.02EPSS
CVE-2025-38501
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with the same IP Repeated connections from clients with the same IP address may exhaust the max connections and prevent other normal client con…

debian debian_linux · linux linux_kernel
0.02EPSS
CVE-2014-4943
Media 6.9

The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.

debian debian_linux · linux linux_kernel · opensuse opensuse · redhat enterprise_linux_server_aus · e altri 2
0.02EPSS