imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2021-47477
High 7.8

In the Linux kernel, the following vulnerability has been resolved: comedi: dt9812: fix DMA buffers on stack USB transfer buffers are typically mapped for DMA and must not be allocated on the stack or transfers will fail. Allocate proper transfer buffers in…

linux linux_kernel
0.01EPSS
CVE-2019-15098
Medium 4.6

drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint descriptor.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_performance_analytics_services · and 4 more
0.01EPSS
CVE-2017-1000380
Medium 5.5

sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a re…

linux linux_kernel
0.01EPSS
CVE-2023-0458
Medium 5.3

A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading …

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2021-3743
High 7.1

An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information…

fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · and 9 more
0.01EPSS
CVE-2024-53226
High 7.5

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() ib_map_mr_sg() allows ULPs to specify NULL as the sg_offset argument. The driver needs to check whether it is a NULL pointer bef…

linux linux_kernel
0.01EPSS
CVE-2013-1929
Medium 4.4

Heap-based buffer overflow in the tg3_read_vpd function in drivers/net/ethernet/broadcom/tg3.c in the Linux kernel before 3.8.6 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via crafted fir…

linux linux_kernel
0.01EPSS
CVE-2017-0331
High 7.8

An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comprom…

google android · linux linux_kernel
0.01EPSS
CVE-2013-7421
Low 2.1

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · oracle linux
0.01EPSS
CVE-2010-2240
High 7.2

The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to…

linux linux_kernel
0.01EPSS
CVE-2001-0317
Low 3.7

Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.

linux linux_kernel
0.01EPSS
CVE-2023-6931
High 7.8

A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_read_…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2024-26782
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the new socket has the same…

linux linux_kernel
0.01EPSS
CVE-2024-46763
High 7.5

In the Linux kernel, the following vulnerability has been resolved: fou: Fix null-ptr-deref in GRO. We observed a null-ptr-deref in fou_gro_receive() while shutting down a host. [0] The NULL pointer is sk->sk_user_data, and the offset 8 is of protocol in s…

linux linux_kernel
0.01EPSS
CVE-2021-47244
High 8.2

In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix out of bounds when parsing TCP options The TCP option parser in mptcp (mptcp_get_options) could read one byte out of bounds. When the length is 1, the execution flow gets into the…

linux linux_kernel
0.01EPSS
CVE-2024-26854
High 7.5

In the Linux kernel, the following vulnerability has been resolved: ice: fix uninitialized dplls mutex usage The pf->dplls.lock mutex is initialized too late, after its first use. Move it to the top of ice_dpll_init. Note that the "err_exit" error path destr…

linux linux_kernel
0.01EPSS
CVE-2012-2119
Medium 5.2

Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length.

linux linux_kernel
0.01EPSS
CVE-2024-24859
Medium 4.6

A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service.

linux linux_kernel
0.01EPSS
CVE-2019-15221
Medium 4.6

An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · and 5 more
0.01EPSS
CVE-2019-15219
Medium 4.6

An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/sisusbvga/sisusb.c driver.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · and 5 more
0.01EPSS
CVE-2006-1342
Low 2.1

net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (1) getsockname, (2) getpeername, and (3) accept functions, which allows local users to obtain portions of potentially sensitive memory.

linux linux_kernel
0.01EPSS
CVE-2024-26880
High 7.8

In the Linux kernel, the following vulnerability has been resolved: dm: call the resume method on internal suspend There is this reported crash when experimenting with the lvm2 testsuite. The list corruption is caused by the fact that the postsuspend and res…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2021-27363
Medium 4.4

An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unpr…

debian debian_linux · linux linux_kernel · netapp cloud_backup · netapp solidfire_baseboard_management_controller_firmware
0.01EPSS
CVE-2020-12657
High 7.8

An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.

linux linux_kernel
0.01EPSS
CVE-2010-3849
Medium 4.7

The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · suse linux_enterprise_desktop · and 3 more
0.01EPSS