imPC@ndo IT

Linux vulnerabilities

14.802 CVE

CVE-2024-38590
High 7.1

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Modify the print level of CQE error Too much print may lead to a panic in kernel. Change ibdev_err() to ibdev_err_ratelimited(), and change the printing level of cqe dump to debug …

linux linux_kernel
0.00EPSS
CVE-2022-48626
High 7.8

In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure could be accessed after it was freed in moxart_remove(), so fix this by saving the base regist…

linux linux_kernel
0.00EPSS
CVE-2022-3633
Low 3.5

A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The ide…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-31829
Medium 5.5

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculativ…

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2020-36312
Medium 5.5

An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.

linux linux_kernel
0.00EPSS
CVE-2019-20934
Medium 5.3

An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c.

linux linux_kernel
0.00EPSS
CVE-2007-3851
Medium 6.0

The drm/i915 component in the Linux kernel before 2.6.22.2, when used with i965G and later chipsets, allows local users with access to an X11 session and Direct Rendering Manager (DRM) to write to arbitrary memory locations and gain privileges via a crafted ba…

linux linux_kernel
0.00EPSS
CVE-2007-3719
Low 2.1

The process scheduler in the Linux kernel 2.6.16 gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuse…

linux linux_kernel
0.00EPSS
CVE-2025-37840
High 7.8

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: brcmnand: fix PM resume warning Fixed warning on PM resume as shown below caused due to uninitialized struct nand_operation that checks chip select field : WARN_ON(op->cs >= na…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2025-37839
High 7.8

In the Linux kernel, the following vulnerability has been resolved: jbd2: remove wrong sb->s_sequence check Journal emptiness is not determined by sb->s_sequence == 0 but rather by sb->s_start == 0 (which is set a few lines above). Furthermore 0 is a valid t…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-53034
High 7.1

In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and size. This would make xlate_pos negative. [ …

linux linux_kernel
0.00EPSS
CVE-2024-27024
High 7.8

In the Linux kernel, the following vulnerability has been resolved: net/rds: fix WARNING in rds_conn_connect_if_down If connection isn't established yet, get_mr() will fail, trigger connection after get_mr().

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2024-26922
High 7.8

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more clearly Verify the parameters of amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2024-26773
High 7.8

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if the group block bitmap is corrupted before using ac_b_ex in ext4_mb_try_best_found() to avoid allo…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-6040
High 7.8

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) value…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-6679
Medium 5.5

A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.

fedoraproject fedora · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2023-23454
Medium 5.5

cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid class…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-33655
Medium 6.7

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-18249
High 7.0

The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2026-31607
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_packets fr…

linux linux_kernel
0.00EPSS
CVE-2025-38209
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue config fails Commit 104d0e2f6222 ("nvme-fabrics: reset admin connection for secure concatenation") modified nvme_tcp_setup_ctrl() to call nvm…

linux linux_kernel
0.00EPSS
CVE-2022-2961
High 7.0

A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate th…

fedoraproject fedora · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · and 3 more
0.00EPSS
CVE-2020-10781
Medium 5.5

A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel me…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2007-3720
Low 2.1

The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result …

linux linux_kernel
0.00EPSS
CVE-1999-0782
Low 2.1

KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.

freebsd freebsd · kde kde · linux linux_kernel
0.00EPSS