imPC@ndo EN

Vulnerabilità Linux

14.774 CVE

CVE-2023-1380
Alta 7.1

A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTR…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp h300s_firmware · e altri 5
0.17EPSS
CVE-2019-6974
Alta 8.1

In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · e altri 20
0.17EPSS
CVE-2017-1000251
Alta 8.0

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code exe…

debian debian_linux · linux linux_kernel · nvidia jetson_tk1 · nvidia jetson_tx1 · e altri 6
0.16EPSS
CVE-2018-11412
Media 5.9

In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated i…

canonical ubuntu_linux · linux linux_kernel
0.16EPSS
CVE-2006-3468
Alta 7.8

Linux kernel 2.6.x, when using both NFS and EXT3, allows remote attackers to cause a denial of service (file system panic) via a crafted UDP packet with a V2 lookup procedure that specifies a bad file handle (inode number), which triggers an error and causes a…

linux linux_kernel
0.16EPSS
CVE-2016-5696
Media 4.8

net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.

google android · linux linux_kernel · oracle vm_server
0.15EPSS
CVE-2009-2692
Alta 7.8

The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to ma…

debian debian_linux · linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · e altri 4
0.15EPSS
CVE-2015-8812
Critica 9.8

drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_real_time_extension
0.15EPSS
CVE-2007-4567
Alta 7.8

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a cra…

linux linux_kernel
0.14EPSS
CVE-2025-21758
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: add RCU protection to mld_newpack() mld_newpack() can be called without RTNL or RCU being held. Note that we no longer can use sock_alloc_send_skb() because ipv6.igmp_sk uses G…

linux linux_kernel
0.14EPSS
CVE-2007-1357
Alta 7.8

The atalk_sum_skb function in AppleTalk for Linux kernel 2.6.x before 2.6.21, and possibly 2.4.x, allows remote attackers to cause a denial of service (crash) via an AppleTalk frame that is shorter than the specified length, which triggers a BUG_ON call when a…

linux linux_kernel
0.14EPSS
CVE-2005-0815
Media 6.4

Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.

linux linux_kernel
0.13EPSS
CVE-2017-10661
Alta 7.0

Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing.

debian debian_linux · linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_aus · e altri 2
0.13EPSS
CVE-2023-32233
Alta 7.8

In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because an…

linux linux_kernel · netapp hci_baseboard_management_controller · redhat enterprise_linux
0.13EPSS
CVE-2024-0582
Alta 7.8

A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on the…

linux linux_kernel
0.13EPSS
CVE-2016-10229
Critica 9.8

udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.

google android · linux linux_kernel
0.13EPSS
CVE-2019-16746
Critica 9.8

An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 1
0.13EPSS
CVE-2009-3613
Alta 7.8

The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of network traffic…

linux linux_kernel
0.12EPSS
CVE-2010-0437
Alta 7.8

The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of serv…

linux linux_kernel
0.12EPSS
CVE-2009-3726
Alta 7.8

The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attri…

linux linux_kernel
0.12EPSS
CVE-2025-37924
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in kerberos authentication Setting sess->user = NULL was introduced to fix the dangling pointer created by ksmbd_free_user. However, it is possible another thread c…

debian debian_linux · linux linux_kernel
0.12EPSS
CVE-2004-0816
Alta 7.5

Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.

linux linux_kernel
0.12EPSS
CVE-2000-0506
Alta 10.0

The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability."

linux linux_kernel
0.11EPSS
CVE-2016-8655
Alta 7.8

Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring …

canonical ubuntu_linux · linux linux_kernel
0.11EPSS
CVE-2009-4272
Alta 7.5

A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and trigger a…

linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · redhat enterprise_linux_server · e altri 2
0.11EPSS