imPC@ndo IT

Linux vulnerabilities

14.787 CVE

CVE-2017-7187
High 7.8

The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a large command size in an SG_NEXT_CMD_LEN ioctl call, lea…

linux linux_kernel
0.00EPSS
CVE-2015-2830
Low 1.9

arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2014-2038
Low 2.1

The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memor…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2014-0069
High 7.2

The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from kernel memor…

linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · redhat enterprise_linux_server · and 5 more
0.00EPSS
CVE-2014-1445
Low 2.1

The wanxl_ioctl function in drivers/net/wan/wanxl.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an ioctl call.

linux linux_kernel
0.00EPSS
CVE-2011-1163
Low 2.1

The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related …

linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · redhat enterprise_linux_server · and 3 more
0.00EPSS
CVE-2010-2798
High 7.8

The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and …

avaya aura_communication_manager · avaya aura_presence_services · avaya aura_session_manager · avaya aura_system_manager · and 11 more
0.00EPSS
CVE-2009-2910
Low 2.1

arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to …

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse opensuse · and 9 more
0.00EPSS
CVE-2008-2358
High 7.2

Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which …

linux linux_kernel
0.00EPSS
CVE-2007-1353
Low 2.1

The setsockopt function in the L2CAP and HCI Bluetooth support in the Linux kernel before 2.4.34.3 allows context-dependent attackers to read kernel memory and obtain sensitive information via unspecified vectors involving the copy_from_user function accessing…

linux linux_kernel
0.00EPSS
CVE-1999-0330
High 7.2

Linux bdash game has a buffer overflow that allows local users to gain root access.

linux linux_kernel
0.00EPSS
CVE-2025-71120
High 7.5

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf A zero length gss_token results in pages == 0 and in_token->pages[0] is NULL. The code unconditionally e…

linux linux_kernel
0.00EPSS
CVE-2025-38057
High 7.5

In the Linux kernel, the following vulnerability has been resolved: espintcp: fix skb leaks A few error paths are missing a kfree_skb.

linux linux_kernel
0.00EPSS
CVE-2024-46697
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure that nfsd4_fattr_args.context is zeroed out If nfsd4_encode_fattr4 ends up doing a "goto out" before we get to checking for the security label, then args.context will be set to …

linux linux_kernel
0.00EPSS
CVE-2023-31084
Medium 5.5

An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test_event(fep…

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h410c_firmware
0.00EPSS
CVE-2022-24958
High 7.8

drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · and 7 more
0.00EPSS
CVE-2021-29657
High 7.4

arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass access control on host OS MSRs when there are nested guests, aka CID-a58d9166a756. This occurs because of a TOCTOU race condition associated …

linux linux_kernel
0.00EPSS
CVE-2021-29650
Medium 5.5

An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a full memory barrier upon the assignment of …

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2020-8647
Medium 6.1

There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.

debian debian_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2018-18386
Low 3.3

drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2017-16649
Medium 6.6

The usbnet_generic_cdc_bind function in drivers/net/usb/cdc_ether.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB device.

linux linux_kernel
0.00EPSS
CVE-2017-7616
Medium 5.5

Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation.

linux linux_kernel
0.00EPSS
CVE-2014-4508
Medium 4.7

arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and system crash) via an invalid syscall number, …

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2013-7026
Medium 4.7

Multiple race conditions in ipc/shm.c in the Linux kernel before 3.12.2 allow local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted application that uses shmctl IPC_RMID operations in…

linux linux_kernel
0.00EPSS
CVE-2012-2319
High 7.2

Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafted HFS plus filesystem, a related issue to CVE-2009-4020.

linux linux_kernel
0.00EPSS