imPC@ndo IT

Linux vulnerabilities

14.802 CVE

CVE-2025-37776
High 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_break_all_levII_oplock() There is a room in smb_break_all_levII_oplock that can cause racy issues when unlocking in the middle of the loop. This patch use re…

linux linux_kernel
0.00EPSS
CVE-2023-2860
Medium 4.4

An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the…

linux linux_kernel
0.00EPSS
CVE-2022-47518
High 7.8

An issue was discovered in the Linux kernel before 6.0.11. Missing validation of the number of channels in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger a heap-based buffer overflow when copying the list of oper…

debian debian_linux · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · and 3 more
0.00EPSS
CVE-2022-3606
Low 3.5

A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to …

linux linux_kernel
0.00EPSS
CVE-2020-36310
Medium 5.5

An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2019-18808
Medium 5.5

A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2017-18200
Medium 5.5

The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demonstrated by fstrim.

linux linux_kernel
0.00EPSS
CVE-2017-8106
Medium 5.5

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointe…

linux linux_kernel
0.00EPSS
CVE-2012-2372
Medium 4.4

The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with …

linux linux_kernel
0.00EPSS
CVE-2025-38617
High 7.8

In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and packet_notifier() When packet_set_ring() releases po->bind_lock, another thread can run packet_notifier() and process an NETDEV_UP event. Thi…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2022-49416
High 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_context(), when we have an old context and the new context's replace_state is set to IEEE80211_CHANCTX_REPLAC…

linux linux_kernel
0.00EPSS
CVE-2023-52886
Medium 6.4

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descri…

linux linux_kernel
0.00EPSS
CVE-2023-26545
Medium 4.7

In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.

debian debian_linux · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · and 3 more
0.00EPSS
CVE-2022-1516
Medium 5.5

A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and continued usage of this connection. This flaw allows a local…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-38205
Low 3.3

drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2020-12652
Medium 4.1

The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to hold an incorrect lock during the ioctl operation and trigger a race condition, i.e., a "double fetch" vulnerability, aka CID-28d76df18f0a. N…

linux linux_kernel
0.00EPSS
CVE-2019-0145
High 7.8

Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

intel ethernet_700_series_software · intel ethernet_controller_710-bm1_firmware · intel ethernet_controller_x710-at2_firmware · intel ethernet_controller_x710-bm2_firmware · and 4 more
0.00EPSS
CVE-2026-23139
High 7.5

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: update last_gc only when GC has been performed Currently last_gc is being updated everytime a new connection is tracked, that means that it is updated even if a GC w…

linux linux_kernel
0.00EPSS
CVE-2022-49160
High 7.5

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash during module load unload test During purex packet handling the driver was incorrectly freeing a pre-allocated structure. Fix this by skipping that entry. System cr…

linux linux_kernel
0.00EPSS
CVE-2024-56651
High 8.8

In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr eve…

linux linux_kernel
0.00EPSS
CVE-2024-50001
High 7.8

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix error path in multi-packet WQE transmit Remove the erroneous unmap in case no DMA mapping was established The multi-packet WQE transmit code attempts to obtain a DMA mapping f…

linux linux_kernel
0.00EPSS
CVE-2024-49894
High 7.1

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index out of bounds in degamma hardware format translation Fixes index out of bounds issue in `cm_helper_translate_curve_to_degamma_hw_format` function. The issue could …

debian debian_linux · linux linux_kernel · siemens simatic_s7-1500_tm_mfp_firmware · siemens sinec_os
0.00EPSS
CVE-2024-26798
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do_set_font() Commit a5a923038d70 (fbdev: fbcon: Properly revert changes when vc_resize() failed) started restoring old font data upon failur…

linux linux_kernel
0.00EPSS
CVE-2022-34495
Medium 5.5

rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

linux linux_kernel
0.00EPSS
CVE-2022-1998
High 7.8

A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privil…

fedoraproject fedora · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · and 4 more
0.00EPSS