imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2022-4744
Alta 7.8

A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate thei…

linux linux_kernel
0.00EPSS
CVE-2019-20810
Media 5.5

go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.

canonical ubuntu_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2017-2618
Media 5.5

A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.

debian debian_linux · linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_desktop · e altri 4
0.00EPSS
CVE-2016-2063
Alta 7.8

Stack-based buffer overflow in the supply_lm_input_write function in drivers/thermal/supply_lm_core.c in the MSM Thermal driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, all…

linux linux_kernel
0.00EPSS
CVE-2010-4242
Media 4.0

The hci_uart_tty_open function in the HCI UART driver (drivers/bluetooth/hci_ldisc.c) in the Linux kernel 2.6.36, and possibly other versions, does not verify whether the tty has a write operation, which allows local users to cause a denial of service (NULL po…

linux linux_kernel
0.00EPSS
CVE-2025-38052
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done Syzbot reported a slab-use-after-free with the following call trace: =====================================================…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-47427
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix iscsi_task use after free Commit d39df158518c ("scsi: iscsi: Have abort handler get ref to conn") added iscsi_get_conn()/iscsi_put_conn() calls during abort handling but the…

linux linux_kernel
0.00EPSS
CVE-2023-52461
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Fix bounds limiting when given a malformed entity If we're given a malformed entity in drm_sched_entity_init()--shouldn't happen, but we verify--with out-of-bounds priority value,…

linux linux_kernel
0.00EPSS
CVE-2019-19531
Media 6.8

In the Linux kernel before 5.2.9, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/yurex.c driver, aka CID-fc05481b2fca.

debian debian_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2016-5829
Alta 7.8

Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · novell suse_linux_enterprise_real_time_extension
0.00EPSS
CVE-2012-2383
Media 4.9

Integer overflow in the i915_gem_execbuffer2 function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-bou…

linux linux_kernel
0.00EPSS
CVE-2006-6128
Bassa 2.1

The ReiserFS functionality in Linux kernel 2.6.18, and possibly other versions, allows local users to cause a denial of service via a malformed ReiserFS file system that triggers memory corruption when a sync is performed.

linux linux_kernel
0.00EPSS
CVE-2026-53151
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modification of the received skbuff in rxrpc_input_soft_acks() and a potential incorrect access of the buffer in a fragmen…

linux linux_kernel
0.00EPSS
CVE-2026-46289
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract_kvec_to_sg Patch series "Fix bugs in extract_iter_to_sg()", v3. Fix bugs in the kvec and user variants of extract_iter_to_sg. This serie…

linux linux_kernel
0.00EPSS
CVE-2026-45988
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a RESPONSE packet gets a temporary failure during processing, it may end up in a partially decrypted state - and then get requeued for a retry…

linux linux_kernel
0.00EPSS
CVE-2026-43384
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

linux linux_kernel
0.00EPSS
CVE-2026-31609
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush() smbd_send_batch_flush() already calls smbd_free_send_io(), so we should not call it again after smbd_post_…

linux linux_kernel
0.00EPSS
CVE-2026-31608
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list() smb_direct_flush_send_list() already calls smb_direct_free_sendmsg(), so we should not call it ag…

linux linux_kernel
0.00EPSS
CVE-2026-31436
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() At the end of this function, d is the traversal cursor of flist, but the code completes found instead. This ca…

linux linux_kernel
0.00EPSS
CVE-2022-38457
Media 6.3

A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the …

linux linux_kernel
0.00EPSS
CVE-2019-3819
Media 4.4

A flaw was found in the Linux kernel in the function hid_debug_events_read() in drivers/hid/hid-debug.c file which may enter an infinite loop with certain parameters passed from a userspace. A local privileged user ("root") can cause a system lock up and a den…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2015-0275
Media 4.9

The ext4_zero_range function in fs/ext4/extents.c in the Linux kernel before 4.1 allows local users to cause a denial of service (BUG) via a crafted fallocate zero-range request.

linux linux_kernel · oracle linux
0.00EPSS
CVE-2006-5751
Alta 7.2

Integer overflow in the get_fdb_entries function in net/bridge/br_ioctl.c in the Linux kernel before 2.6.18.4 allows local users to execute arbitrary code via a large maxnum value in an ioctl request.

linux linux_kernel
0.00EPSS
CVE-2026-43402
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent use-after-free Guillaume reported crashes via corrupted RCU callback function pointers during KUnit testing. The crash was traced back to t…

linux linux_kernel
0.00EPSS
CVE-2022-2153
Media 5.5

A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to …

debian debian_linux · fedoraproject fedora · linux linux_kernel · redhat enterprise_linux
0.00EPSS