imPC@ndo IT

Linux vulnerabilities

14.802 CVE

CVE-2024-49953
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix crash caused by calling __xfrm_state_delete() twice The km.state is not checked in driver's delayed work. When xfrm_state_check_expire() is called, the state can be reset to X…

linux linux_kernel
0.00EPSS
CVE-2024-40970
High 7.8

In the Linux kernel, the following vulnerability has been resolved: Avoid hw_desc array overrun in dw-axi-dmac I have a use case where nr_buffers = 3 and in which each descriptor is composed by 3 segments, resulting in the DMA channel descs_allocated to be 9…

linux linux_kernel
0.00EPSS
CVE-2023-4207
High 7.8

A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation. When fw_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instance of th…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2022-3303
Medium 4.7

A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw t…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-40490
High 7.0

A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp aff_a250_firmware · and 13 more
0.00EPSS
CVE-2020-27830
Medium 5.5

A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr deref crash.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2016-5340
High 7.8

The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended…

google android · linux linux_kernel
0.00EPSS
CVE-2026-46125
High 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station if connection prep fails If connection preparation fails for MLO connections, then the interface is completely reset to non-MLD. In this case, we must not keep…

linux linux_kernel
0.00EPSS
CVE-2025-39894
High 7.5

In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm When send a broadcast packet to a tap device, which was added to a bridge, br_nf_local_in() is called to…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2025-39880
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: libceph: fix invalid accesses to ceph_connection_v1_info There is a place where generic code in messenger.c is reading and another place where it is writing to con->v1 union member without c…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2024-41000
High 7.8

In the Linux kernel, the following vulnerability has been resolved: block/ioctl: prefer different overflow check Running syzkaller with the newly reintroduced signed integer overflow sanitizer shows this report: [ 62.982337] ------------[ cut here ]------…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2024-40974
High 7.8

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Enforce hcall result buffer validity and size plpar_hcall(), plpar_hcall9(), and related functions expect callers to provide valid result buffers of certain minimum size. Cu…

linux linux_kernel
0.00EPSS
CVE-2024-39509
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: HID: core: remove unnecessary WARN_ON() in implement() Syzkaller hit a warning [1] in a call to implement() when trying to write a value into a field of smaller size in an output report. Si…

linux linux_kernel
0.00EPSS
CVE-2024-26630
High 7.1

In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix folio read-after-free in cache walk In cachestat, we access the folio from the page cache's xarray to compute its page offset, and check for its dirty and writeback flags.…

linux linux_kernel
0.00EPSS
CVE-2023-52436
High 7.8

In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. This eliminates the fragile assumption that the unused xattr space is always …

linux linux_kernel
0.00EPSS
CVE-2021-4037
Medium 4.4

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a sce…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-4028
High 7.8

A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local access to setup a socket to listen on a high port allowing for a list element to be used after free. Given the ability to execute code, a lo…

linux linux_kernel · suse linux_enterprise
0.00EPSS
CVE-2022-1852
Medium 5.5

A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU.

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2020-14351
High 7.8

A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability i…

debian debian_linux · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2025-40039
High 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access The 'sess->rpc_handle_list' XArray manages RPC handles within a ksmbd session. Access to this list is intended to be protected by 'sess->r…

linux linux_kernel
0.00EPSS
CVE-2022-49581
High 7.8

In the Linux kernel, the following vulnerability has been resolved: be2net: Fix buffer overflow in be_get_module_eeprom be_cmd_read_port_transceiver_data assumes that it is given a buffer that is at least PAGE_DATA_LEN long, or twice that if the module suppo…

linux linux_kernel
0.00EPSS
CVE-2024-36484
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: net: relax socket state check at accept time. Christoph reported the following splat: WARNING: CPU: 1 PID: 772 at net/ipv4/af_inet.c:761 __inet_accept+0x1f4/0x4a0 Modules linked in: CPU: 1 …

linux linux_kernel
0.00EPSS
CVE-2024-27399
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, th…

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2024-26652
Medium 4.1

In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), Callback function pdsc_auxbus_dev_release c…

linux linux_kernel
0.00EPSS
CVE-2023-1281
High 7.8

Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()' is called with the de…

linux linux_kernel
0.00EPSS