imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2018-19985
Media 4.6

The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read i…

debian debian_linux · linux linux_kernel · netapp active_iq_performance_analytics_services · netapp element_software_management_node
0.01EPSS
CVE-2016-8483
Media 5.5

An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user…

linux linux_kernel
0.01EPSS
CVE-2024-27388
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix some memleaks in gssx_dec_option_array The creds and oa->data need to be freed in the error-handling paths after their allocation. So this patch add these deallocations in the co…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2014-2851
Media 6.9

Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an impr…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2012-0957
Media 4.9

The override_release function in kernel/sys.c in the Linux kernel before 3.4.16 allows local users to obtain sensitive information from kernel stack memory via a uname system call in conjunction with a UNAME26 personality.

linux linux_kernel
0.01EPSS
CVE-2008-0009
Bassa 2.1

The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.

linux linux_kernel
0.01EPSS
CVE-2004-1333
Bassa 2.1

Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.

linux linux_kernel · redhat fedora_core · redhat linux
0.01EPSS
CVE-2024-36912
Critica 9.6

In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an err…

linux linux_kernel
0.01EPSS
CVE-2021-27364
Alta 7.1

An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp cloud_backup · e altri 2
0.01EPSS
CVE-2022-4543
Media 5.5

A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on TLB timing for Intel systems.

linux linux_kernel
0.01EPSS
CVE-2021-47103
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syzbot reported various issues around early demux, one being included in this changelog [1] sk->sk_rx_dst is using RCU protection without clea…

linux linux_kernel
0.01EPSS
CVE-2012-3430
Bassa 2.1

The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system …

linux linux_kernel
0.01EPSS
CVE-2016-2854
Alta 7.8

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

linux linux_kernel
0.01EPSS
CVE-2019-19922
Media 5.5

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 10
0.01EPSS
CVE-2016-6516
Alta 7.4

Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch…

linux linux_kernel
0.01EPSS
CVE-2011-0714
Media 5.7

Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, r…

linux linux_kernel · redhat enterprise_linux
0.01EPSS
CVE-2013-1796
Media 6.8

The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host O…

linux linux_kernel
0.01EPSS
CVE-2015-2877
Bassa 3.3

Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) at…

linux linux_kernel · redhat enterprise_linux
0.01EPSS
CVE-2023-4004
Alta 7.8

A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their pri…

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h300s · e altri 4
0.01EPSS
CVE-2014-3180
Critica 9.1

In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code pa…

google chrome_os · linux linux_kernel
0.01EPSS
CVE-2023-52340
Alta 7.5

The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a raw socket.

linux linux_kernel
0.01EPSS
CVE-2022-3526
Media 5.3

A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function macvlan_handle_frame of the file drivers/net/macvlan.c of the component skb. The manipulation leads to memory leak. The attack can be initiated remotel…

linux linux_kernel
0.01EPSS
CVE-2009-2847
Media 4.9

The do_sigaltstack function in kernel/signal.c in Linux kernel 2.4 through 2.4.37 and 2.6 before 2.6.31-rc5, when running on 64-bit systems, does not clear certain padding bytes from a structure, which allows local users to obtain sensitive information from th…

linux kernel · linux linux_kernel
0.01EPSS
CVE-2025-37899
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the…

linux linux_kernel
0.01EPSS
CVE-2021-29154
Alta 7.8

BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp cloud_backup · e altri 9
0.01EPSS