imPC@ndo IT

Linux vulnerabilities

14.802 CVE

CVE-2021-3501
High 7.1

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this v…

fedoraproject fedora · linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · and 15 more
0.00EPSS
CVE-2020-28915
Medium 5.8

A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.

linux linux_kernel
0.00EPSS
CVE-2017-1000111
High 7.8

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. T…

debian debian_linux · linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_desktop · and 5 more
0.00EPSS
CVE-2017-6353
Medium 5.5

net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. …

linux linux_kernel
0.00EPSS
CVE-2016-5400
Medium 4.3

Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR …

linux linux_kernel
0.00EPSS
CVE-2016-2383
Medium 5.5

The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading…

canonical ubuntu_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2014-7843
Medium 4.9

The __clear_user function in arch/arm64/lib/clear_user.S in the Linux kernel before 3.17.4 on the ARM64 platform allows local users to cause a denial of service (system crash) by reading one byte beyond a /dev/zero page boundary.

linux linux_kernel
0.00EPSS
CVE-2014-7842
Medium 4.9

Race condition in arch/x86/kvm/x86.c in the Linux kernel before 3.17.4 allows guest OS users to cause a denial of service (guest OS crash) via a crafted application that performs an MMIO transaction or a PIO transaction to trigger a guest userspace emulation e…

linux linux_kernel
0.00EPSS
CVE-2014-8086
Medium 4.7

Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT fla…

linux linux_kernel · suse suse_linux_enterprise_server
0.00EPSS
CVE-2022-47946
Medium 5.5

An issue was discovered in the Linux kernel 5.10.x before 5.10.155. A use-after-free in io_sqpoll_wait_sq in fs/io_uring.c allows an attacker to crash the kernel, resulting in denial of service. finish_wait can be skipped. An attack can occur in some situation…

linux linux_kernel
0.00EPSS
CVE-2019-19058
Medium 4.7

A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2017-14051
Medium 4.4

An integer overflow in the qla2x00_sysfs_write_optrom_ctl function in drivers/scsi/qla2xxx/qla_attr.c in the Linux kernel through 4.12.10 allows local users to cause a denial of service (memory corruption and system crash) by leveraging root access.

linux linux_kernel
0.00EPSS
CVE-2017-11472
High 7.1

The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR …

linux linux_kernel
0.00EPSS
CVE-2017-8831
Medium 6.4

The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact by changing a certain sequence-num…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2005-0179
Low 2.1

Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.

linux linux_kernel
0.00EPSS
CVE-2002-1319
Low 2.1

The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.

linux linux_kernel · trustix secure_linux
0.00EPSS
CVE-2022-50363
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: skmsg: pass gfp argument to alloc_sk_msg() syzbot found that alloc_sk_msg() could be called from a non sleepable context. sk_psock_verdict_recv() uses rcu_read_lock() protection. We need th…

linux linux_kernel
0.00EPSS
CVE-2025-37749
High 8.2

In the Linux kernel, the following vulnerability has been resolved: net: ppp: Add bound checking for skb data on ppp_sync_txmung Ensure we have enough data in linear buffer from skb before accessing initial bytes. This prevents potential out-of-bounds access…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2025-21725
High 7.5

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix oops due to unset link speed It isn't guaranteed that NETWORK_INTERFACE_INFO::LinkSpeed will always be set by the server, so the client must handle any values and then preve…

linux linux_kernel
0.00EPSS
CVE-2024-56656
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips The 5760X (P7) chip's HW GRO/LRO interface is very similar to that of the previous generation (5750X or P5). However, the agg…

linux linux_kernel
0.00EPSS
CVE-2024-35969
High 8.8

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr Although ipv6_get_ifaddr walks inet6_addr_lst under the RCU lock, it still means hlist_for_each_entry_rcu can return an ite…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-26605
High 7.8

In the Linux kernel 6.0.8, there is a use-after-free in inode_cgwb_move_to_attached in fs/fs-writeback.c, related to __list_del_entry_valid.

linux linux_kernel
0.00EPSS
CVE-2022-2959
High 7.0

A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. T…

linux linux_kernel
0.00EPSS
CVE-2021-23134
High 7.8

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW capability.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp cloud_backup · and 6 more
0.00EPSS
CVE-2017-18193
Medium 5.5

fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a denial of service (BUG) via an application with multiple threads.

linux linux_kernel
0.00EPSS