imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2019-15211
Medium 4.6

An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · and 5 more
0.01EPSS
CVE-2010-4250
Medium 4.9

Memory leak in the inotify_init1 function in fs/notify/inotify/inotify_user.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory consumption) via vectors involving failed attempts to create files.

linux linux_kernel
0.01EPSS
CVE-2018-9568
High 7.8

In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Version…

canonical ubuntu_linux · google android · linux linux_kernel · redhat enterprise_linux_desktop · and 5 more
0.01EPSS
CVE-2024-26817
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of doing the multiplication which might overflow.

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2019-19927
Medium 6.0

In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c…

linux linux_kernel · opensuse leap
0.01EPSS
CVE-2021-3864
High 7.0

A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then ha…

debian debian_linux · linux linux_kernel · redhat enterprise_linux
0.01EPSS
CVE-2018-10878
High 7.8

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · redhat enterprise_linux_desktop · and 2 more
0.01EPSS
CVE-2024-41036
High 7.5

In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Fix deadlock with the SPI chip variant When SMP is enabled and spinlocks are actually functional then there is a deadlock with the 'statelock' spinlock between ks8851_start_xmit…

linux linux_kernel
0.01EPSS
CVE-2024-36288
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-memory…

linux linux_kernel
0.01EPSS
CVE-2009-0746
Medium 4.9

The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext…

linux linux_kernel
0.01EPSS
CVE-1999-0720
Medium 4.6

The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.

linux linux_kernel
0.01EPSS
CVE-2009-3888
Medium 4.9

The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management unit, allows local users to cause a denial of service (OOPS) via an application that attempts to allocate a large amount of memory.

linux linux_kernel
0.01EPSS
CVE-2025-4598
Medium 4.7

A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/…

debian debian_linux · linux linux_kernel · oracle linux · redhat enterprise_linux · and 2 more
0.01EPSS
CVE-2024-38605
High 7.8

In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduced a WARN_ON() for a NULL module pointer passed at snd_card o…

linux linux_kernel
0.01EPSS
CVE-2024-26828
Critical 9.4

In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size we need. However, th…

linux linux_kernel
0.01EPSS
CVE-2024-36031
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem fo…

linux linux_kernel
0.01EPSS
CVE-2021-47274
High 7.8

In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542…

linux linux_kernel
0.01EPSS
CVE-2022-45934
High 7.8

An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h300s_firmware · and 4 more
0.01EPSS
CVE-2021-47515
High 7.5

In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving interface index into the IPv4 socket control block (v5.16-rc4, net…

linux linux_kernel
0.01EPSS
CVE-2024-26584
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our requests to the crypto API, crypto_aead_{encrypt,decrypt} can return -EBUSY in…

linux linux_kernel
0.01EPSS
CVE-2017-0523
High 7.0

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process.…

google android · linux linux_kernel
0.01EPSS
CVE-2019-25160
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), the other in netlbl_bitmap_walk(). Both errors are embarassin…

linux linux_kernel
0.01EPSS
CVE-2005-3807
Medium 4.9

Memory leak in the VFS file lease handling in locks.c in Linux kernels 2.6.10 to 2.6.15 allows local users to cause a denial of service (memory exhaustion) via certain Samba activities that cause an fasync entry to be re-allocated by the fcntl_setlease functio…

linux linux_kernel
0.01EPSS
CVE-2021-47131
High 8.1

In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix use-after-free after the TLS device goes down and up When a netdev with active TLS offload goes down, tls_device_down is called to stop the offload and tear down the TLS context…

linux linux_kernel
0.01EPSS
CVE-2021-47001
High 7.5

In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix cwnd update ordering After a reconnect, the reply handler is opening the cwnd (and thus enabling more RPC Calls to be sent) /before/ rpcrdma_post_recvs() can post enough Receiv…

linux linux_kernel
0.01EPSS