imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2019-19529
Media 6.3

In the Linux kernel before 5.3.11, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c driver, aka CID-4d6636498c41.

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2019-12379
Media 5.5

An issue was discovered in con_insert_unipair in drivers/tty/vt/consolemap.c in the Linux kernel through 5.1.5. There is a memory leak in a certain case of an ENOMEM outcome of kmalloc. NOTE: This id is disputed as not being an issue

linux linux_kernel
0.00EPSS
CVE-2018-10675
Alta 7.8

The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_server · e altri 5
0.00EPSS
CVE-2017-14106
Media 5.5

The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.

linux linux_kernel
0.00EPSS
CVE-2017-10911
Media 6.5

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields i…

linux linux_kernel
0.00EPSS
CVE-2015-5257
Media 4.9

drivers/usb/serial/whiteheat.c in the Linux kernel before 4.2.4 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted USB device. NOTE: this ID was incorr…

linux linux_kernel
0.00EPSS
CVE-2026-43379
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close() opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being accessed after rcu_read_unlock() has been called. This cre…

linux linux_kernel
0.00EPSS
CVE-2026-43376
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for oplock_info ksmbd currently frees oplock_info immediately using kfree(), even though it is accessed under RCU read-side critical sections in…

linux linux_kernel
0.00EPSS
CVE-2026-43184
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: rnbd-srv: Zero the rsp buffer before using it Before using the data buffer to send back the response message, zero it completely. This prevents any stray bytes to be picked up by the client …

linux linux_kernel
0.00EPSS
CVE-2026-31589
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_invalidate() We can only call filemap_free_folio() if we have a reference to (or hold a lock on) the mapping. Otherwise, we've already remove…

linux linux_kernel
0.00EPSS
CVE-2020-36694
Media 6.7

An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with th…

linux linux_kernel
0.00EPSS
CVE-2021-3653
Alta 8.8

A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" …

debian debian_linux · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2019-12454
Alta 7.8

An issue was discovered in wcd9335_codec_enable_dec in sound/soc/codecs/wcd9335.c in the Linux kernel through 5.1.5. It uses kstrndup instead of kmemdup_nul, which allows attackers to have an unspecified impact via unknown vectors. NOTE: The vendor disputes th…

linux linux_kernel
0.00EPSS
CVE-2019-12381
Media 5.5

An issue was discovered in ip_ra_control in net/ipv4/ip_sockglue.c in the Linux kernel through 5.1.5. There is an unchecked kmalloc of new_ra, which might allow an attacker to cause a denial of service (NULL pointer dereference and system crash). NOTE: this is…

linux linux_kernel
0.00EPSS
CVE-2011-4330
Alta 7.2

Stack-based buffer overflow in the hfs_mac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field.

linux linux_kernel
0.00EPSS
CVE-2009-3939
Alta 7.1

The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.

avaya aura_application_enablement_services · avaya aura_communication_manager · avaya aura_session_manager · avaya aura_sip_enablement_services · e altri 14
0.00EPSS
CVE-2004-0565
Bassa 2.1

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

gentoo linux · linux linux_kernel · mandrakesoft mandrake_linux · mandrakesoft mandrake_linux_corporate_server · e altri 2
0.00EPSS
CVE-2004-0003
Media 4.6

Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."

linux linux_kernel
0.00EPSS
CVE-2026-43452
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: guard option walkers against 1-byte tail reads When the last byte of options is a non-single-byte option kind, walkers that advance with i += op[i + 1] ? : 1 can read op…

linux linux_kernel
0.00EPSS
CVE-2026-43383
Critica 9.4

In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

linux linux_kernel
0.00EPSS
CVE-2026-31668
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths in seg6 lwtunnel The seg6 lwtunnel uses a single dst_cache per encap route, shared between seg6_input_core() and seg6_output_core(). These…

linux linux_kernel
0.00EPSS
CVE-2026-31448
Critica 9.4

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data On the mkdir/mknod path, when mapping logical blocks to physical blocks, if inserting a new extent into the extent tree fails (in this exam…

linux linux_kernel
0.00EPSS
CVE-2024-58053
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix handling of received connection abort Fix the handling of a connection abort that we've received. Though the abort is at the connection level, it needs propagating to the calls o…

linux linux_kernel
0.00EPSS
CVE-2024-57932
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: gve: guard XDP xmit NDO on existence of xdp queues In GVE, dedicated XDP queues only exist when an XDP program is installed and the interface is up. As such, the NDO XDP XMIT callback should…

linux linux_kernel
0.00EPSS
CVE-2024-46796
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_set_path_size() If smb2_compound_op() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() before retryi…

linux linux_kernel
0.00EPSS