imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2018-18690
Medium 5.5

In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2018-7755
Medium 5.5

An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use…

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2024-38570
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix potential glock use-after-free on unmount When a DLM lockspace is released and there ares still locks in that lockspace, DLM will unlock those locks automatically. Commit fb6791d1…

linux linux_kernel
0.01EPSS
CVE-2017-0620
High 7.0

An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pr…

google android · linux linux_kernel
0.01EPSS
CVE-2022-49664
High 7.5

In the Linux kernel, the following vulnerability has been resolved: tipc: move bc link creation back to tipc_node_create Shuang Li reported a NULL pointer dereference crash: [] BUG: kernel NULL pointer dereference, address: 0000000000000068 [] RIP: 0010…

linux linux_kernel
0.01EPSS
CVE-2024-38612
High 7.0

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix invalid unregister error path The error path of seg6_init() is wrong in case CONFIG_IPV6_SEG6_LWTUNNEL is not defined. In that case if seg6_hmac_init() fails, the genl_unregist…

linux linux_kernel
0.01EPSS
CVE-2021-47478
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs image When isofs image is suitably corrupted isofs_read_inode() can read data beyond the end of buffer. Sanity-check the directory entry le…

linux linux_kernel
0.01EPSS
CVE-2024-35884
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: udp: do not accept non-tunnel GSO skbs landing in a tunnel When rx-udp-gro-forwarding is enabled UDP packets might be GROed when being forwarded. If such packets might land in a tunnel this …

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2024-35880
High 7.8

In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: hold io_buffer_list reference over mmap If we look up the kbuf, ensure that it doesn't get unregistered until after we're done with it. Since we're inside mmap, we cannot safe…

linux linux_kernel
0.01EPSS
CVE-2024-56645
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_session_new(): fix skb reference counting Since j1939_session_skb_queue() does an extra skb_get() for each new skb, do the same for the initial one in j1939_session_new() t…

linux linux_kernel
0.01EPSS
CVE-2019-15217
Medium 4.6

An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · and 5 more
0.01EPSS
CVE-2026-64269
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE th…

linux linux_kernel
0.01EPSS
CVE-2024-47739
High 7.5

In the Linux kernel, the following vulnerability has been resolved: padata: use integer wrap around to prevent deadlock on seq_nr overflow When submitting more than 2^32 padata objects to padata_do_serial, the current sorting implementation incorrectly sorts…

linux linux_kernel
0.01EPSS
CVE-2024-26665
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the following splat, BUG: KASAN: slab-out-of-bounds in do_csum+0x…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2023-52441
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out of bounds in init_smb2_rsp_hdr() If client send smb2 negotiate request and then send smb1 negotiate request, init_smb2_rsp_hdr is called for smb1 negotiate request since need_…

linux linux_kernel
0.01EPSS
CVE-2019-19332
Medium 6.1

An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or proc…

linux linux_kernel · redhat enterprise_linux
0.01EPSS
CVE-2016-2067
High 7.8

drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows atta…

google android · linux linux_kernel
0.01EPSS
CVE-2019-7222
Medium 5.5

The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · and 14 more
0.01EPSS
CVE-2021-47486
High 7.5

In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix potential NULL dereference The bpf_jit_binary_free() function requires a non-NULL argument. When the RISC-V BPF JIT fails to converge in NR_JIT_ITERATIONS steps, jit_data->he…

linux linux_kernel
0.01EPSS
CVE-2023-52628
High 7.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: exthdr: fix 4-byte stack OOB write If priv->len is a multiple of 4, then dst[len / 4] can write past the destination array which leads to stack corruption. This constru…

linux linux_kernel
0.01EPSS
CVE-2016-8436
High 7.8

An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compr…

google android · linux linux_kernel
0.01EPSS
CVE-2023-52454
High 7.5

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length If the host sends an H2CData command with an invalid DATAL, the kernel may crash in nvmet_tcp_build_pdu_iovec(). Unab…

linux linux_kernel
0.01EPSS
CVE-2026-46195
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DACL pointers parse_sec_desc(), build_sec_desc(), and the chown path in id_mode_to_cifs_acl() all add the server-supplied dacloffset to pntsd…

linux linux_kernel
0.01EPSS
CVE-2014-0131
Low 2.9

Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.

linux linux_kernel · opensuse evergreen · suse linux_enterprise_server
0.01EPSS
CVE-2014-7970
Medium 5.5

The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both argumen…

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_server
0.01EPSS