imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2013-1848
Medium 6.2

fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.

linux linux_kernel
0.01EPSS
CVE-2016-2064
High 7.8

sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (buffer…

linux linux_kernel
0.01EPSS
CVE-2005-0504
Medium 4.6

Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.

linux linux_kernel
0.01EPSS
CVE-2021-47433
High 8.1

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix abort logic in btrfs_replace_file_extents Error injection testing uncovered a case where we'd end up with a corrupt file system with a missing extent in the middle of a file. Thi…

linux linux_kernel
0.01EPSS
CVE-2021-37576
High 7.8

arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.

fedoraproject fedora · linux linux_kernel
0.01EPSS
CVE-2017-0619
High 7.0

An elevation of privilege vulnerability in the Qualcomm pin controller driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged…

google android · linux linux_kernel
0.01EPSS
CVE-2013-6382
Medium 4.0

Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_AT…

linux linux_kernel
0.01EPSS
CVE-2006-2935
Medium 4.6

The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that trigg…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2026-46133
High 7.5

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject unknown opcodes before ICRC processing Even after applying commit 7244491dab34 ("RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv"), a single unauthenticated…

linux linux_kernel
0.01EPSS
CVE-2018-10323
Medium 5.5

The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2017-0451
Medium 4.7

An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc…

google android · linux linux_kernel
0.01EPSS
CVE-2013-6381
Medium 6.9

Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that …

linux linux_kernel
0.01EPSS
CVE-2024-26641
High 8.6

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize ipv6h var…

debian debian_linux · linux linux_kernel · netapp a150_firmware · netapp a220_firmware · and 10 more
0.01EPSS
CVE-2022-3619
Low 3.5

A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to memory leak. It is recommended…

linux linux_kernel
0.01EPSS
CVE-2021-33656
Medium 6.8

When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.

debian debian_linux · linux linux_kernel · openatom openeuler
0.01EPSS
CVE-2024-49999
High 7.5

In the Linux kernel, the following vulnerability has been resolved: afs: Fix the setting of the server responding flag In afs_wait_for_operation(), we set transcribe the call responded flag to the server record that we used after doing the fileserver iterati…

linux linux_kernel
0.01EPSS
CVE-2018-20669
High 7.8

An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to over…

canonical ubuntu_linux · linux linux_kernel · netapp cn1610_firmware · netapp hci_management_node · and 2 more
0.01EPSS
CVE-2018-10124
Medium 5.5

The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2011-1593
Medium 4.9

Multiple integer overflows in the next_pidmap function in kernel/pid.c in the Linux kernel before 2.6.38.4 allow local users to cause a denial of service (system crash) via a crafted (1) getdents or (2) readdir system call.

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_aus · and 4 more
0.01EPSS
CVE-2024-50145
High 7.5

In the Linux kernel, the following vulnerability has been resolved: octeon_ep: Add SKB allocation failures handling in __octep_oq_process_rx() build_skb() returns NULL in case of a memory allocation failure so handle it inside __octep_oq_process_rx() to avoi…

linux linux_kernel
0.01EPSS
CVE-2022-42722
Medium 5.5

In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.01EPSS
CVE-2024-35821
Medium 5.5

In the Linux kernel, the following vulnerability has been resolved: ubifs: Set page uptodate in the correct place Page cache reads are lockless, so setting the freshly allocated page uptodate before we've overwritten it with the data it's supposed to have in…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2020-13974
High 7.8

An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2018-18021
High 7.1

arch/arm64/kvm/guest.c in KVM in the Linux kernel before 4.18.12 on the arm64 platform mishandles the KVM_SET_ON_REG ioctl. This is exploitable by attackers who can create virtual machines. An attacker can arbitrarily redirect the hypervisor flow of control (w…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2008-2729
Medium 4.9

arch/x86_64/lib/copy_user.S in the Linux kernel before 2.6.19 on some AMD64 systems does not erase destination memory locations after an exception during kernel memory copy, which allows local users to obtain sensitive information.

linux linux_kernel
0.01EPSS