imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2026-22998
High 7.5

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec Commit efa56305908b ("nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length") added ttag bounds checkin…

linux linux_kernel
0.01EPSS
CVE-2024-26582
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt_done releases them, an…

linux linux_kernel
0.01EPSS
CVE-2023-28772
Medium 6.7

An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.

linux linux_kernel
0.01EPSS
CVE-2021-28038
Medium 6.5

An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host…

debian debian_linux · linux linux_kernel · netapp cloud_backup · netapp solidfire_baseboard_management_controller_firmware
0.01EPSS
CVE-2019-11487
High 7.8

The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, if about 140 GiB of RAM exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h, include/linux/pipe_fs_i.h, kern…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2021-47259
High 7.8

In the Linux kernel, the following vulnerability has been resolved: NFS: Fix use-after-free in nfs4_init_client() KASAN reports a use-after-free when attempting to mount two different exports through two different NICs that belong to the same server. Olga w…

linux linux_kernel
0.01EPSS
CVE-2020-12659
Medium 6.7

An issue was discovered in the Linux kernel before 5.6.7. xdp_umem_reg in net/xdp/xdp_umem.c has an out-of-bounds write (by a user with the CAP_NET_ADMIN capability) because of a lack of headroom validation.

linux linux_kernel · netapp active_iq_unified_manager · netapp aff_baseboard_management_controller · netapp cloud_backup · and 4 more
0.01EPSS
CVE-2018-20856
High 7.8

An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an __blk_drain_queue() use-after-free because a certain error case is mishandled.

linux linux_kernel
0.01EPSS
CVE-2020-12826
Medium 5.3

A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can s…

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux · redhat enterprise_mrg
0.01EPSS
CVE-2021-31916
Medium 6.7

An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel before 5.12. A bound check failure allows an attacker with special user (CAP_SYS_ADMIN) privilege to gain access t…

debian debian_linux · linux linux_kernel · redhat enterprise_linux
0.01EPSS
CVE-2022-48686
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix UAF when detecting digest errors We should also bail from the io_work loop when we set rd_enabled to true, so we don't attempt to read data from the socket when the TCP stream …

linux linux_kernel
0.01EPSS
CVE-2019-14284
Medium 6.2

In the Linux kernel before 5.2.3, drivers/block/floppy.c allows a denial of service by setup_format_params division-by-zero. Two consecutive ioctls can trigger the bug: the first one should set the drive geometry with .sect and .rate values that make F_SECT_PE…

linux linux_kernel
0.01EPSS
CVE-2014-8134
Low 3.3

The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted applicatio…

canonical ubuntu_linux · linux linux_kernel · opensuse evergreen · opensuse opensuse · and 2 more
0.01EPSS
CVE-2010-3848
Medium 6.9

Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large number of iovec structures.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · suse linux_enterprise_desktop · and 3 more
0.01EPSS
CVE-1999-1441
Low 2.1

Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it.

linux linux_kernel
0.01EPSS
CVE-1999-0138
High 7.2

The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.

apple a_ux · digital osf_1 · freebsd freebsd · hp hp-ux · and 5 more
0.01EPSS
CVE-2021-44733
High 7.0

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · and 8 more
0.01EPSS
CVE-2014-3186
Medium 6.9

Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (…

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2024-26804
High 7.8

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: prevent perpetual headroom growth syzkaller triggered following kasan splat: BUG: KASAN: use-after-free in __skb_flow_dissect+0x19d1/0x7a50 net/core/flow_dissector.c:1170 Rea…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2022-45888
Medium 6.4

An issue was discovered in the Linux kernel through 6.0.9. drivers/char/xillybus/xillyusb.c has a race condition and use-after-free during physical removal of a USB device.

linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · netapp h410s_firmware · and 2 more
0.01EPSS
CVE-2009-0676
Low 2.1

The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request.

linux linux_kernel
0.01EPSS
CVE-2022-49670
High 7.5

In the Linux kernel, the following vulnerability has been resolved: linux/dim: Fix divide by 0 in RDMA DIM Fix a divide 0 error in rdma_dim_stats_compare() when prev->cpe_ratio == 0. CallTrace: Hardware name: H3C R4900 G3/RS33M2C9S, BIOS 2.00.37P21 03/12/…

linux linux_kernel
0.01EPSS
CVE-2024-44986
High 8.1

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to m…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2019-19039
Medium 5.5

__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2019-3701
Medium 4.4

An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can cr…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS