IT

Linux vulnerabilities

14.802 CVE

CVE-2022-48803
High 7.3

In the Linux kernel, the following vulnerability has been resolved: phy: ti: Fix missing sentinel for clk_div_table _get_table_maxdiv() tries to access "clk_div_table" array out of bound defined in phy-j721e-wiz.c. Add a sentinel entry to prevent the followi…

linux linux_kernel
0.00EPSS
CVE-2024-40989
High 7.8

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Disassociate vcpus from redistributor region on teardown When tearing down a redistributor region, make sure we don't have any dangling pointer to that region stored in a vcpu.

linux linux_kernel
0.00EPSS
CVE-2024-40984
High 7.8

In the Linux kernel, the following vulnerability has been resolved: ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine." Undo the modifications made in commit d410ee5109a1 ("ACPICA: avoid "Info: mapping multiple BARs. Your kernel …

linux linux_kernel
0.00EPSS
CVE-2023-52439
High 7.8

In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 ------------------------------------------------------- uio_unregister_device uio_open idev = idr_find() device_unregister(&idev->de…

linux linux_kernel
0.00EPSS
CVE-2023-33288
Medium 4.7

An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.

linux linux_kernel
0.00EPSS
CVE-2023-22995
High 7.8

In the Linux kernel before 5.17, an error path in dwc3_qcom_acpi_register_core in drivers/usb/dwc3/dwc3-qcom.c lacks certain platform_device_put and kfree calls.

linux linux_kernel
0.00EPSS
CVE-2023-23559
High 7.8

In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.

debian debian_linux · linux linux_kernel · netapp hci_baseboard_management_controller
0.00EPSS
CVE-2022-0322
Medium 5.5

A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, lead…

fedoraproject fedora · linux linux_kernel · oracle communications_cloud_native_core_binding_support_function · oracle communications_cloud_native_core_network_exposure_function · and 1 more
0.00EPSS
CVE-2021-30178
Medium 5.5

An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987.

fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2016-10044
High 7.8

The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system ca…

google android · linux linux_kernel
0.00EPSS
CVE-2016-3841
High 7.3

The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.

google android · linux linux_kernel
0.00EPSS
CVE-2026-43215
High 8.8

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lo…

linux linux_kernel
0.00EPSS
CVE-2026-43198
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is…

linux linux_kernel
0.00EPSS
CVE-2022-49698
High 7.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: use get_random_u32 instead of prandom bh might occur while updating per-cpu rnd_state from user context, ie. local_out path. BUG: using smp_processor_id() in preemptible [0000000…

linux linux_kernel
0.00EPSS
CVE-2022-49688
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: afs: Fix dynamic root getattr The recent patch to make afs_getattr consult the server didn't account for the pseudo-inodes employed by the dynamic root-type afs superblock not having a volum…

linux linux_kernel
0.00EPSS
CVE-2022-49059
High 7.8

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: add flush_workqueue to prevent uaf Our detector found a concurrent use-after-free bug when detaching an NCI device. The main reason for this bug is the unexpected scheduling betwee…

linux linux_kernel
0.00EPSS
CVE-2024-40968
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: MIPS: Octeon: Add PCIe link status check The standard PCIe configuration read-write interface is used to access the configuration space of the peripheral PCIe devices of the mips processor a…

linux linux_kernel
0.00EPSS
CVE-2024-39507
High 7.0

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash problem in concurrent scenario When link status change, the nic driver need to notify the roce driver to handle this event, but at this time, the roce driver may …

linux linux_kernel
0.00EPSS
CVE-2024-39499
High 7.1

In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted that event_msg is controlled by user-space, event_msg->event_data.event is passed to event_deliver() a…

linux linux_kernel
0.00EPSS
CVE-2024-0841
Medium 6.6

A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2023-7192
Medium 5.5

A memory leak problem was found in ctnetlink_create_conntrack in net/netfilter/nf_conntrack_netlink.c in the Linux Kernel. This issue may allow a local attacker with CAP_NET_ADMIN privileges to cause a denial of service (DoS) attack due to a refcount overflow.…

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2023-4015
High 7.8

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. On an error when building a nftables rule, deactivating immediate expressions in nft_immediate_deactivate() can lead un…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-0597
Medium 5.5

A flaw possibility of memory leak in the Linux kernel cpu_entry_area mapping of X86 CPU data to memory was found in the way user can guess location of exception stack(s) or other important data. A local user could use this flaw to get access to some important …

linux linux_kernel
0.00EPSS
CVE-2022-47519
High 7.8

An issue was discovered in the Linux kernel before 6.0.11. Missing validation of IEEE80211_P2P_ATTR_OPER_CHANNEL in drivers/net/wireless/microchip/wilc1000/cfg80211.c in the WILC1000 wireless driver can trigger an out-of-bounds write when parsing the channel l…

debian debian_linux · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · and 3 more
0.00EPSS
CVE-2025-37874
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: net: ngbe: fix memory leak in ngbe_probe() error path When ngbe_sw_init() is called, memory is allocated for wx->rss_key in wx_init_rss_key(). However, in ngbe_probe() function, the subseque…

linux linux_kernel
0.00EPSS