imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2026-31557
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: nvmet: move async event work off nvmet-wq For target nvmet_ctrl_free() flushes ctrl->async_event_work. If nvmet_ctrl_free() runs on nvmet-wq, the flush re-enters workqueue completion for the…

linux linux_kernel
0.00EPSS
CVE-2026-23451
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: bonding: prevent potential infinite loop in bond_header_parse() bond_header_parse() can loop if a stack of two bonding devices is setup, because skb->dev always points to the hierarchy top. …

linux linux_kernel
0.00EPSS
CVE-2017-12188
Alta 7.8

arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a…

linux linux_kernel
0.00EPSS
CVE-2014-8159
Media 6.9

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical me…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2011-4621
Media 5.5

The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop.

linux linux_kernel
0.00EPSS
CVE-2010-1436
Media 4.9

gfs2 in the Linux kernel 2.6.18, and possibly other versions, does not properly handle when the gfs2_quota struct occupies two separate pages, which allows local users to cause a denial of service (kernel panic) via certain manipulations that cause an out-of-b…

linux linux_kernel
0.00EPSS
CVE-2009-0834
Bassa 3.6

The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain s…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 8
0.00EPSS
CVE-2008-3911
Alta 7.2

The proc_do_xprt function in net/sunrpc/sysctl.c in the Linux kernel 2.6.26.3 does not check the length of a certain buffer obtained from userspace, which allows local users to overflow a stack-based buffer and have unspecified other impact via a crafted read …

linux linux_kernel
0.00EPSS
CVE-2006-1528
Media 4.9

Linux kernel before 2.6.13 allows local users to cause a denial of service (crash) via a dio transfer from the sg driver to memory mapped (mmap) IO space.

linux linux_kernel
0.00EPSS
CVE-2005-3806
Media 6.6

The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggeri…

linux linux_kernel
0.00EPSS
CVE-2004-0447
Alta 7.2

Unknown vulnerability in Linux before 2.4.26 for IA64 allows local users to cause a denial of service, with unknown impact. NOTE: due to a typo, this issue was accidentally assigned CVE-2004-0477. This is the proper candidate to use for the Linux local DoS.

linux linux_kernel
0.00EPSS
CVE-2025-22059
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: udp: Fix multiple wraparounds of sk->sk_rmem_alloc. __udp_enqueue_schedule_skb() has the following condition: if (atomic_read(&sk->sk_rmem_alloc) > sk->sk_rcvbuf) goto drop; sk…

linux linux_kernel
0.00EPSS
CVE-2024-26926
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: binder: check offset alignment in binder_get_object() Commit 6d98eb95b450 ("binder: avoid potential data leakage when copying txn") introduced changes to how binder objects are copied. In do…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-42739
Media 6.7

The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.

debian debian_linux · fedoraproject fedora · linux linux_kernel · oracle communications_cloud_native_core_binding_support_function · e altri 4
0.00EPSS
CVE-2019-20812
Media 5.5

An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_blk_tmo() function in net/packet/af_packet.c can result in a denial of service (CPU consumption and soft lockup) in a certain failure case involving TPACKET_V3, aka CID-b43d1f9f7067.…

linux linux_kernel
0.00EPSS
CVE-2018-16276
Alta 7.8

An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2014-4171
Media 4.7

mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demo…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2013-1819
Media 4.6

The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux kernel before 3.7.6 does not validate block numbers, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leve…

linux linux_kernel
0.00EPSS
CVE-2013-0231
Media 4.9

The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log me…

linux linux_kernel · xen xen
0.00EPSS
CVE-2011-1169
Alta 7.2

Array index error in the asihpi_hpi_ioctl function in sound/pci/asihpi/hpioctl.c in the AudioScience HPI driver in the Linux kernel before 2.6.38.1 might allow local users to cause a denial of service (memory corruption) or possibly gain privileges via a craft…

linux linux_kernel
0.00EPSS
CVE-2001-1395
Bassa 3.6

Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact.

linux linux_kernel
0.00EPSS
CVE-2001-1396
Bassa 3.6

Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact.

linux linux_kernel
0.00EPSS
CVE-2001-1397
Bassa 2.1

The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory.

linux linux_kernel
0.00EPSS
CVE-2024-44973
Alta 8.1

In the Linux kernel, the following vulnerability has been resolved: mm, slub: do not call do_slab_free for kfence object In 782f8906f805 the freeing of kfence objects was moved from deep inside do_slab_free to the wrapper functions outside. This is a nice ch…

linux linux_kernel
0.00EPSS
CVE-2015-0274
Alta 7.2

The XFS implementation in the Linux kernel before 3.15 improperly uses an old size value during remote attribute replacement, which allows local users to cause a denial of service (transaction overrun and data corruption) or possibly gain privileges by leverag…

linux linux_kernel
0.00EPSS