imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2016-8636
High 7.8

Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unsp…

linux linux_kernel
0.01EPSS
CVE-2016-8397
Medium 5.5

An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user p…

linux linux_kernel
0.01EPSS
CVE-2016-2061
High 7.8

Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (array overf…

linux linux_kernel
0.01EPSS
CVE-2017-0444
High 7.0

An elevation of privilege vulnerability in the Realtek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. …

google android · linux linux_kernel
0.01EPSS
CVE-2019-8956
High 7.8

In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handling SCTP_SENDALL flag can be exploited to corrupt memory.

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2016-1576
High 7.8

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid prog…

canonical ubuntu_core · canonical ubuntu_linux · canonical ubuntu_touch · linux linux_kernel
0.01EPSS
CVE-2022-48748
High 7.5

In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping and stats are disabled, untagged or priority-tagged ingress frame will go to check pvid st…

linux linux_kernel
0.01EPSS
CVE-2022-3640
Medium 5.5

A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patc…

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.01EPSS
CVE-2014-1739
Low 2.1

The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read a…

canonical ubuntu_linux · linux linux_kernel · suse linux_enterprise_high_availability_extension · suse suse_linux_enterprise_desktop · and 1 more
0.01EPSS
CVE-2020-29661
High 7.8

A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.

broadcom fabric_operating_system · debian debian_linux · fedoraproject fedora · linux linux_kernel · and 8 more
0.01EPSS
CVE-2025-38191
High 7.5

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set ->PreviousSessionId on kerberos session setup stage, NULL pointer dereference error will happen. Since sess->use…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2022-0812
Medium 4.3

An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c in the Linux Kernel. This flaw allows an attacker with normal user privileges to leak kernel information.

linux linux_kernel
0.01EPSS
CVE-2021-4204
High 7.1

An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.

debian debian_linux · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · and 4 more
0.01EPSS
CVE-2011-2723
Medium 5.7

The skb_gro_header_slow function in include/linux/netdevice.h in the Linux kernel before 2.6.39.4, when Generic Receive Offload (GRO) is enabled, resets certain fields in incorrect situations, which allows remote attackers to cause a denial of service (system …

linux linux_kernel
0.01EPSS
CVE-2015-3290
High 7.2

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which allows local users to gain privileges by triggering an NMI within a certain instruction window.

linux linux_kernel
0.01EPSS
CVE-2019-15792
High 7.1

In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->priv…

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2013-6376
Medium 5.2

The recalculate_apic_map function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (host OS crash) via a crafted ICR write operation in x2apic mode.

linux linux_kernel
0.01EPSS
CVE-2020-28588
Medium 5.5

An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in…

linux linux_kernel
0.01EPSS
CVE-2007-1000
High 7.2

The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference.

linux linux_kernel
0.01EPSS
CVE-2023-39179
High 7.5

A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this to …

linux linux_kernel
0.01EPSS
CVE-2023-1192
Medium 6.5

A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses i…

linux linux_kernel · redhat enterprise_linux
0.01EPSS
CVE-2008-5079
Medium 4.9

net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corr…

linux linux_kernel
0.01EPSS
CVE-2019-9162
High 7.8

In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ASN.1 length checks (aka an array index error), making out-of-bounds read and write operations possible, leading to an OOPS or local privile…

canonical ubuntu_linux · linux linux_kernel · netapp cn1610_firmware · netapp hci_management_node · and 2 more
0.01EPSS
CVE-2011-1478
Medium 5.7

The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL po…

linux linux_kernel
0.01EPSS
CVE-2019-19241
High 7.8

In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709. This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an attacker can bypass intended res…

linux linux_kernel
0.01EPSS