imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2005-3359
Medium 4.9

The atm module in Linux kernel 2.6 before 2.6.14 allows local users to cause a denial of service (panic) via certain socket calls that produce inconsistent reference counts for loadable protocol modules.

linux linux_kernel
0.01EPSS
CVE-2019-15031
Medium 4.4

In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via an interrupt. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction tbe…

canonical ubuntu_linux · linux linux_kernel · opensuse leap · redhat enterprise_linux
0.01EPSS
CVE-2014-0102
Medium 5.2

The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause a denial of service (OOPS) via crafted keyctl commands.

linux linux_kernel
0.01EPSS
CVE-2010-3865
High 7.2

Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request, which tri…

linux linux_kernel · opensuse opensuse · suse linux_enterprise_high_availability_extension · suse linux_enterprise_real_time
0.01EPSS
CVE-2005-2490
Medium 4.6

Stack-based buffer overflow in the sendmsg function call in the Linux kernel 2.6 before 2.6.13.1 allows local users to execute arbitrary code by calling sendmsg and modifying the message contents in another thread.

linux linux_kernel
0.01EPSS
CVE-2026-43493
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that value and filtering out EINPROGRESS notifications.

linux linux_kernel
0.01EPSS
CVE-2024-53176
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: During unmount, ensure all cached dir instances drop their dentry The unmount process (cifs_kill_sb() calling close_all_cached_dirs()) can race with various cached directory operations,…

linux linux_kernel
0.01EPSS
CVE-2024-50154
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). Martin KaFai Lau reported use-after-free [0] in reqsk_timer_handler(). """ We are seeing a use-after-free from a bpf prog at…

linux linux_kernel
0.01EPSS
CVE-2024-53177
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: prevent use-after-free due to open_cached_dir error paths If open_cached_dir() encounters an error parsing the lease from the server, the error handling may race with receiving a lease …

linux linux_kernel
0.01EPSS
CVE-2023-52885
High 8.1

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() After the listener svc_sock is freed, and before invoking svc_tcp_accept() for the established child sock, there is a window that the newsock r…

linux linux_kernel
0.01EPSS
CVE-2016-4581
Medium 5.5

fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series of mount s…

canonical ubuntu_linux · linux linux_kernel · oracle linux
0.01EPSS
CVE-2016-4482
Medium 6.2

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl c…

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · novell suse_linux_enterprise_debuginfo · and 7 more
0.01EPSS
CVE-2016-3156
Medium 5.5

The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses.

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_debuginfo · novell suse_linux_enterprise_desktop · and 6 more
0.01EPSS
CVE-2026-64125
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX path on GENET hardware once MAC EEE becomes active. RX traffic stops flowing while…

linux linux_kernel
0.01EPSS
CVE-2026-64089
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len batadv_piv_tt::last_changeset_len len was declared as s16, but the field is never intended to hold a negative value. When a value greater than…

linux linux_kernel
0.01EPSS
CVE-2026-52986
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strtoul Replace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(), and ct_sip_parse_request() with a new sip_parse_port() helper th…

linux linux_kernel
0.01EPSS
CVE-2021-32078
High 7.1

An Out-of-Bounds Read was discovered in arch/arm/mach-footbridge/personal-pci.c in the Linux kernel through 5.12.11 because of the lack of a check for a value that shouldn't be negative, e.g., access to element -2 of an array, aka CID-298a58e165e4.

linux linux_kernel
0.01EPSS
CVE-2018-16658
Medium 6.1

An issue was discovered in the Linux kernel before 4.18.6. An information leak in cdrom_ioctl_drive_status in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking.…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2014-9644
Low 2.1

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · oracle linux
0.01EPSS
CVE-2013-2234
Low 2.1

The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a…

linux linux_kernel
0.01EPSS
CVE-2022-49770
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it'…

linux linux_kernel
0.01EPSS
CVE-2024-46865
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized.

linux linux_kernel
0.01EPSS
CVE-2019-19807
High 7.8

In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly c…

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2018-15594
Medium 5.5

arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2007-1388
Medium 4.4

The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option leng…

linux linux_kernel
0.01EPSS