imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2017-10663
Alta 7.8

The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors.

linux linux_kernel
0.00EPSS
CVE-2015-5706
Media 4.6

Use-after-free vulnerability in the path_openat function in fs/namei.c in the Linux kernel 3.x and 4.x before 4.0.4 allows local users to cause a denial of service or possibly have unspecified other impact via O_TMPFILE filesystem operations that leverage a du…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2014-9419
Bassa 2.1

The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread Local Storage (TLS) descriptors are loaded before proceeding with other steps, which makes it easier for local users to bypass the ASLR prot…

linux linux_kernel
0.00EPSS
CVE-2007-2875
Bassa 2.1

Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpu…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2006-3745
Alta 7.2

Unspecified vulnerability in the sctp_make_abort_user function in the SCTP implementation in Linux 2.6.x before 2.6.17.10 and 2.4.23 up to 2.4.33 allows local users to cause a denial of service (panic) and possibly gain root privileges via unknown attack vecto…

linux linux_kernel
0.00EPSS
CVE-2004-0001
Alta 7.2

Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.

linux linux_kernel
0.00EPSS
CVE-2026-53198
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL A deferred byte-range lock (an SMB2_LOCK that blocks) registers an async work on conn->async_requests via setup_async_…

linux linux_kernel
0.00EPSS
CVE-2026-43203
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: atm: fore200e: fix use-after-free in tasklets during device removal When the PCA-200E or SBA-200E adapter is being detached, the fore200e is deallocated. However, the tx_tasklet or rx_taskle…

linux linux_kernel
0.00EPSS
CVE-2026-31598
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix possible deadlock between unlink and dio_end_io_write ocfs2_unlink takes orphan dir inode_lock first and then ip_alloc_sem, while in ocfs2_dio_end_io_write, it acquires these lock…

linux linux_kernel
0.00EPSS
CVE-2024-44992
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: smb/client: avoid possible NULL dereference in cifs_free_subrequest() Clang static checker (scan-build) warning: cifsglob.h:line 890, column 3 Access to field 'ops' results in a dereferenc…

linux linux_kernel
0.00EPSS
CVE-2024-41046
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times.

linux linux_kernel
0.00EPSS
CVE-2020-12653
Alta 7.8

An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of service because of an incorrect memcpy and buffer overflow, ak…

debian debian_linux · linux linux_kernel · netapp a700s_firmware · netapp active_iq_unified_manager · e altri 18
0.00EPSS
CVE-2019-15919
Bassa 3.3

An issue was discovered in the Linux kernel before 5.0.10. SMB2_write in fs/cifs/smb2pdu.c has a use-after-free.

linux linux_kernel · opensuse leap
0.00EPSS
CVE-2017-18204
Media 5.5

The ocfs2_setattr function in fs/ocfs2/file.c in the Linux kernel before 4.14.2 allows local users to cause a denial of service (deadlock) via DIO requests.

linux linux_kernel
0.00EPSS
CVE-2013-6431
Media 4.7

The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 does not properly implement error-code encoding, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN cap…

linux linux_kernel
0.00EPSS
CVE-2011-0712
Alta 7.2

Multiple buffer overflows in the caiaq Native Instruments USB audio functionality in the Linux kernel before 2.6.38-rc4-next-20110215 might allow attackers to cause a denial of service or possibly have unspecified other impact via a long USB device name, relat…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2010-3448
Media 4.9

drivers/platform/x86/thinkpad_acpi.c in the Linux kernel before 2.6.34 on ThinkPad devices, when the X.Org X server is used, does not properly restrict access to the video output control state, which allows local users to cause a denial of service (system hang…

linux linux_kernel
0.00EPSS
CVE-2010-3880
Media 4.9

net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contai…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2025-38120
Critica 9.4

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo_avx2: fix initial map fill If the first field doesn't cover the entire start map, then we must zero out the remainder, else we leak those bits into the next match ro…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2020-25656
Media 4.1

A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is …

debian debian_linux · linux linux_kernel · redhat enterprise_linux · starwindsoftware starwind_virtual_san
0.00EPSS
CVE-2019-20422
Media 5.5

In the Linux kernel before 5.3.4, fib6_rule_lookup in net/ipv6/ip6_fib.c mishandles the RT6_LOOKUP_F_DST_NOREF flag in a reference-count decision, leading to (for example) a crash that was identified by syzkaller, aka CID-7b09c2d052db.

linux linux_kernel
0.00EPSS
CVE-2017-15868
Alta 7.8

The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2016-10147
Media 5.5

crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5).

linux linux_kernel
0.00EPSS
CVE-2015-4167
Media 4.7

The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted UDF files…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2013-7268
Media 4.9

The ipx_recvmsg function in net/ipx/af_ipx.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory v…

linux linux_kernel
0.00EPSS