imPC@ndo IT

Linux vulnerabilities

14.775 CVE

CVE-2018-18710
Medium 5.5

An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. T…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2015-8374
Medium 4.0

fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.

linux linux_kernel
0.01EPSS
CVE-2026-64113
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb…

linux linux_kernel
0.01EPSS
CVE-2026-64102
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Reject MPA FPDU length underflow before signed receive math A malicious connected siw peer can send an iWARP FPDU whose MPA length field (c_hdr->mpa_len, 16 bit big-endian, peer-co…

linux linux_kernel
0.01EPSS
CVE-2026-63800
Critical 9.8

In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() When hitting the NFS_LAYOUT_RETURN branch in pnfs_update_layout(), the code calls pnfs_prepare_to_retry_layoutget(lo). If it succeeds, pnfs_p…

linux linux_kernel
0.01EPSS
CVE-2026-52974
High 7.5

In the Linux kernel, the following vulnerability has been resolved: net: tls: fix strparser anchor skb leak on offload RX setup failure When tls_set_device_offload_rx() fails at tls_dev_add(), the error path calls tls_sw_free_resources_rx() to clean up the S…

linux linux_kernel
0.01EPSS
CVE-2026-46110
High 7.5

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Prevent NULL deref when RX memory exhausted The CPU receives frames from the MAC through conventional DMA: the CPU allocates buffers for the MAC, then the MAC fills them and ret…

linux linux_kernel
0.01EPSS
CVE-2022-1055
High 7.8

A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · and 8 more
0.01EPSS
CVE-2014-4656
Medium 4.6

Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (1) index values in the snd_ctl_add funct…

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · and 5 more
0.01EPSS
CVE-2013-4592
Medium 4.0

Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service (memory consumption) by leveraging certain device access to trigger movement of memory slots.

linux linux_kernel
0.01EPSS
CVE-2013-1767
Medium 6.2

Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol …

linux linux_kernel
0.01EPSS
CVE-2005-0531
Low 2.1

The atm_get_addr function in addr.c for Linux kernel 2.6.10 and 2.6.11 before 2.6.11-rc4 may allow local users to trigger a buffer overflow via negative arguments.

linux linux_kernel
0.01EPSS
CVE-2003-0246
Low 3.6

The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.

linux linux_kernel
0.01EPSS
CVE-2026-31476
High 8.2

In the Linux kernel, the following vulnerability has been resolved: ksmbd: do not expire session on binding failure When a multichannel session binding request fails (e.g. wrong password), the error path unconditionally sets sess->state = SMB2_SESSION_EXPIRE…

linux linux_kernel
0.00EPSS
CVE-2025-37926
High 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_session_rpc_open A UAF issue can occur due to a race condition between ksmbd_session_rpc_open() and __session_rpc_close(). Add rpc_lock to the session to p…

linux linux_kernel
0.00EPSS
CVE-2024-53073
High 7.5

In the Linux kernel, the following vulnerability has been resolved: NFSD: Never decrement pending_async_copies on error The error flow in nfsd4_copy() calls cleanup_async_copy(), which already decrements nn->pending_async_copies.

linux linux_kernel
0.00EPSS
CVE-2024-35970
Medium 6.3

In the Linux kernel, the following vulnerability has been resolved: af_unix: Clear stale u->oob_skb. syzkaller started to report deadlock of unix_gc_lock after commit 4090fa373f0e ("af_unix: Replace garbage collection algorithm."), but it just uncovers the b…

linux linux_kernel
0.00EPSS
CVE-2019-11191
Low 2.5

The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass ASLR on setuid a.out programs (if any exist) because install_exec_creds() is called too late in load_aout_binary() in fs/binfmt_aout.c, and t…

linux linux_kernel
0.00EPSS
CVE-2014-9892
Medium 5.5

The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly initialize a timestamp data structure, which allows attackers to obtain sens…

google android · linux linux_kernel
0.00EPSS
CVE-2014-3183
Medium 6.9

Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a craf…

linux linux_kernel
0.00EPSS
CVE-2012-0028
High 7.2

The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local users to cause a denial of service or possibly gain privileges by writing to a memory location in a child proce…

linux linux_kernel
0.00EPSS
CVE-2009-0322
Medium 4.9

drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2005-3181
Low 2.1

The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · mandriva linux
0.00EPSS
CVE-2005-0001
Medium 6.9

Race condition in the page fault handler (fault.c) for Linux kernel 2.2.x to 2.2.7, 2.4 to 2.4.29, and 2.6 to 2.6.10, when running on multiprocessor machines, allows local users to execute arbitrary code via concurrent threads that share the same virtual memor…

linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_desktop · trustix secure_linux
0.00EPSS
CVE-2016-3699
High 7.4

The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the init…

linux linux_kernel · redhat enterprise_mrg · redhat linux
0.00EPSS