imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2009-1914
Medium 4.9

The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc64 platform allows local users to cause a denial of service (system crash) by reading the /proc/iomem file, related to uninitialized pointers…

linux linux_kernel
0.01EPSS
CVE-2026-64257
Critical 9.1

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[…

linux linux_kernel
0.01EPSS
CVE-2024-41073
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: nvme: avoid double free special payload If a discard request needs to be retried, and that retry may fail before a new special payload is added, a double free will result. Clear the RQF_SPEC…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2020-36516
Medium 5.9

An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session.

linux linux_kernel · netapp bootstrap_os · netapp cloud_volumes_ontap_mediator · netapp e-series_santricity_os_controller · and 14 more
0.01EPSS
CVE-2017-7518
Medium 5.5

A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process insi…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · redhat enterprise_linux · and 5 more
0.01EPSS
CVE-2016-8414
Medium 4.7

An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising…

google android · linux linux_kernel
0.01EPSS
CVE-2023-52887
High 7.5

In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: enhanced error handling for tightly received RTS messages in xtp_rx_rts_session_new This patch enhances error handling in scenarios with RTS (Request to Send) messages arriv…

linux linux_kernel
0.01EPSS
CVE-2021-47179
High 7.5

In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix a NULL pointer dereference in pnfs_mark_matching_lsegs_return() Commit de144ff4234f changes _pnfs_return_layout() to call pnfs_mark_matching_lsegs_return() passing NULL as the str…

linux linux_kernel
0.01EPSS
CVE-2018-10840
Medium 6.6

Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by operating on a mounted crafted ext4 image.

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux
0.01EPSS
CVE-2024-50286
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-use-after-free in ksmbd_smb2_session_create There is a race condition between ksmbd_smb2_session_create and ksmbd_expire_session. This patch add missing sessions_table_lock w…

linux linux_kernel
0.01EPSS
CVE-2021-43389
Medium 5.5

An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c.

debian debian_linux · linux linux_kernel · oracle communications_cloud_native_core_binding_support_function · oracle communications_cloud_native_core_network_exposure_function · and 2 more
0.01EPSS
CVE-2024-35835
High 7.8

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a double-free in arfs_create_groups When `in` allocated by kvzalloc fails, arfs_create_groups will free ft->g and return an error. However, arfs_create_table, the only caller …

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2020-25221
High 7.8

get_gate_page in mm/gup.c in the Linux kernel 5.7.x and 5.8.x before 5.8.7 allows privilege escalation because of incorrect reference counting (caused by gate page mishandling) of the struct page that backs the vsyscall page. The result is a refcount underflow…

linux linux_kernel · netapp cloud_backup · netapp hci_compute_node · netapp solidfire\ · and 3 more
0.01EPSS
CVE-2022-49048
High 7.5

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix panic when forwarding a pkt with no in6 dev kongweibin reported a kernel panic in ip6_forward() when input interface has no in6 dev associated. The following tc commands were used…

linux linux_kernel
0.01EPSS
CVE-2022-48658
High 7.5

In the Linux kernel, the following vulnerability has been resolved: mm: slub: fix flush_cpu_slab()/__free_slab() invocations in task context. Commit 5a836bf6b09f ("mm: slub: move flush_cpu_slab() invocations __free_slab() invocations out of IRQ context") mov…

linux linux_kernel
0.01EPSS
CVE-2019-15291
Medium 4.6

An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe function in the drivers/media/usb/b2c2/flexcop-usb.c driver.

linux linux_kernel
0.01EPSS
CVE-2021-47189
High 7.8

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory ordering between normal and ordered work functions Ordered work functions aren't guaranteed to be handled by the same thread which executed the normal work functions. The o…

linux linux_kernel
0.01EPSS
CVE-2025-22039
High 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the existing bounds check i…

linux linux_kernel
0.01EPSS
CVE-2023-52775
High 8.2

In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid data corruption caused by decline We found a data corruption issue during testing of SMC-R on Redis applications. The benchmark has a low probability of reporting a strange e…

linux linux_kernel
0.01EPSS
CVE-2024-50276
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: net: vertexcom: mse102x: Fix possible double free of TX skb The scope of the TX skb is wider than just mse102x_tx_frame_spi(), so in case the TX skb room needs to be expanded, we should free…

linux linux_kernel
0.01EPSS
CVE-2023-39176
Medium 5.8

A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacke…

linux linux_kernel
0.01EPSS
CVE-2022-49280
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: NFSD: prevent underflow in nfssvc_decode_writeargs() Smatch complains: fs/nfsd/nfsxdr.c:341 nfssvc_decode_writeargs() warn: no lower bound on 'args->len' Change the type to unsigned to p…

linux linux_kernel
0.01EPSS
CVE-2022-49194
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: Use stronger register read/writes to assure ordering GCC12 appears to be much smarter about its dependency tracking and is aware that the relaxed variants are just normal load…

linux linux_kernel
0.01EPSS
CVE-2024-35863
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in is_valid_oplock_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.

linux linux_kernel
0.01EPSS
CVE-2024-35862
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_network_name_deleted() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF.

linux linux_kernel
0.01EPSS