imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2008-2826
Medium 4.9

Integer overflow in the sctp_getsockopt_local_addrs_old function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) functionality in the Linux kernel before 2.6.25.9 allows local users to cause a denial of service (resource consumption and…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse
0.00EPSS
CVE-2022-49051
Medium 6.8

In the Linux kernel, the following vulnerability has been resolved: net: usb: aqc111: Fix out-of-bounds accesses in RX fixup aqc111_rx_fixup() contains several out-of-bounds accesses that can be triggered by a malicious (or defective) USB device, in particul…

linux linux_kernel
0.00EPSS
CVE-2023-2236
High 7.8

A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a us…

linux linux_kernel · netapp hci_baseboard_management_controller
0.00EPSS
CVE-2022-1263
Medium 5.5

A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of serv…

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2022-32296
Low 3.3

The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. This occurs because of use of Algorithm 4 ("Double-Hash Port Selection Algorithm") of RFC 6056.

linux linux_kernel
0.00EPSS
CVE-2022-24959
Medium 5.5

An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-17805
High 7.8

The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitial…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse leap · and 4 more
0.00EPSS
CVE-2016-10208
Medium 4.3

The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 im…

linux linux_kernel
0.00EPSS
CVE-2014-3646
Medium 5.5

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse evergreen · and 2 more
0.00EPSS
CVE-2014-3182
Medium 6.9

Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provid…

linux linux_kernel
0.00EPSS
CVE-2010-3067
Medium 4.9

Integer overflow in the do_io_submit function in fs/aio.c in the Linux kernel before 2.6.36-rc4-next-20100915 allows local users to cause a denial of service or possibly have unspecified other impact via crafted use of the io_submit system call.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · and 4 more
0.00EPSS
CVE-2018-16885
Medium 4.7

A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a sys…

linux linux_kernel · redhat enterprise_linux_server
0.00EPSS
CVE-2018-12930
High 7.8

ntfs_end_buffer_async_read in the ntfs.ko filesystem driver in the Linux kernel 4.15.0 allows attackers to trigger a stack-based out-of-bounds write and cause a denial of service (kernel oops or panic) or possibly have unspecified other impact via a crafted nt…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2010-4169
Medium 4.9

Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.

fedoraproject fedora · linux linux_kernel · opensuse opensuse · suse linux_enterprise_desktop · and 2 more
0.00EPSS
CVE-2009-1072
Medium 4.9

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · and 7 more
0.00EPSS
CVE-2008-2944
Medium 4.9

Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the GNU GDB tests…

fedoraproject fedora_core · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2006-1052
Low 2.1

The selinux_ptrace logic in hooks.c in SELinux for Linux 2.6.6 allows local users with ptrace permissions to change the tracer SID to an SID of another process.

linux linux_kernel
0.00EPSS
CVE-2004-0138
Medium 4.9

The ELF loader in Linux kernel 2.4 before 2.4.25 allows local users to cause a denial of service (crash) via a crafted ELF file with an interpreter with an invalid arch (architecture), which triggers a BUG() when an invalid VMA is unmapped.

linux linux_kernel
0.00EPSS
CVE-2001-1392
Low 2.1

The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by unloading and reloading the drivers.

linux linux_kernel
0.00EPSS
CVE-2001-1393
Low 2.1

Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).

linux linux_kernel
0.00EPSS
CVE-2026-64091
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated by first checking the number of VLANs which have at least one TT entry. A new buffer with the correct …

linux linux_kernel
0.00EPSS
CVE-2026-53284
High 7.5

In the Linux kernel, the following vulnerability has been resolved: btrfs: only release the dirty pages io tree after successful writes [WARNING] With extra warning on dirty extent buffers at umount (aka, the next patch in the series), test case generic/388 …

linux linux_kernel
0.00EPSS
CVE-2026-53026
High 7.5

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg In nfsd4_add_rdaccess_to_wrdeleg, if fp->fi_fds[O_RDONLY] is already set by another thread, __nfs4_file_get_access sho…

linux linux_kernel
0.00EPSS
CVE-2026-46137
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() helper is executed as a timer callback in softirq context. To avoid any data races, the socket lock needs to be hel…

linux linux_kernel
0.00EPSS
CVE-2026-43125
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of…

linux linux_kernel
0.00EPSS