imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2011-1476
Media 4.0

Integer underflow in the Open Sound System (OSS) subsystem in the Linux kernel before 2.6.39 on unspecified non-x86 platforms allows local users to cause a denial of service (memory corruption) by leveraging write access to /dev/sequencer.

linux linux_kernel
0.00EPSS
CVE-2009-3620
Alta 7.8

The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possi…

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse opensuse · e altri 4
0.00EPSS
CVE-2007-6206
Bassa 2.1

The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow loca…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 8
0.00EPSS
CVE-2006-3741
Media 4.9

The perfmonctl system call (sys_perfmonctl) in Linux kernel 2.4.x and 2.6 before 2.6.18, when running on Itanium systems, does not properly track the reference count for file descriptors, which allows local users to cause a denial of service (file descriptor c…

linux linux_kernel
0.00EPSS
CVE-2026-22997
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts Since j1939_session_deactivate_activate_next() in j1939_tp_rxtimer() is called only when …

linux linux_kernel
0.00EPSS
CVE-2022-1016
Media 5.5

A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivi…

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2022-0487
Media 5.5

A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions…

debian debian_linux · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2021-28039
Media 6.5

An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical …

linux linux_kernel · netapp cloud_backup · netapp solidfire_baseboard_management_controller_firmware · xen xen
0.00EPSS
CVE-2014-9731
Bassa 2.1

The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing a symlink target's name along with a trailing \0 character, which allows local users to obtain sensitive information via a crafted filesyste…

linux linux_kernel
0.00EPSS
CVE-2004-0495
Alta 7.2

Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.

avaya converged_communications_server · avaya intuity_audix · avaya modular_messaging_message_storage_server · avaya s8300 · e altri 14
0.00EPSS
CVE-2026-23226
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add chann_lock to protect ksmbd_chann_list xarray ksmbd_chann_list xarray lacks synchronization, allowing use-after-free in multi-channel sessions (between lookup_chann_list() and ksm…

linux linux_kernel
0.00EPSS
CVE-2025-21629
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets The blamed commit disabled hardware offoad of IPv6 packets with extension headers on devices that advertise NETIF_F_IPV6_CSUM, bas…

linux linux_kernel
0.00EPSS
CVE-2020-12114
Media 4.7

A pivot_root race condition in fs/namespace.c in the Linux kernel 4.4.x before 4.4.221, 4.9.x before 4.9.221, 4.14.x before 4.14.178, 4.19.x before 4.19.119, and 5.x before 5.3 allows local users to cause a denial of service (panic) by corrupting a mountpoint …

linux linux_kernel
0.00EPSS
CVE-2017-5576
Alta 7.8

Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a V…

linux linux_kernel
0.00EPSS
CVE-2017-5546
Alta 7.8

The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to cause a denial of service (duplicate freelist entries and system crash) or possibly have unspecified other impact in opportunistic circumstan…

linux linux_kernel
0.00EPSS
CVE-2016-9191
Media 5.5

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, a…

linux linux_kernel
0.00EPSS
CVE-2015-8539
Alta 7.8

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted…

canonical ubuntu_linux · linux linux_kernel · suse linux_enterprise_real_time_extension
0.00EPSS
CVE-2013-2892
Media 4.7

drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted devic…

linux linux_kernel
0.00EPSS
CVE-2010-2524
Alta 7.8

The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof…

canonical ubuntu_linux · linux linux_kernel · suse suse_linux_enterprise_desktop · suse suse_linux_enterprise_server · e altri 1
0.00EPSS
CVE-2006-5173
Bassa 2.1

Linux kernel does not properly save or restore EFLAGS during a context switch, or reset the flags when creating new threads, which allows local users to cause a denial of service (process crash), as demonstrated using a process that sets the Alignment Check fl…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2006-4538
Media 4.9

Linux kernel 2.6.17 and earlier, when running on IA64 or SPARC platforms, allows local users to cause a denial of service (crash) via a malformed ELF file that triggers memory maps that cross region boundaries.

linux linux_kernel
0.00EPSS
CVE-2005-3109
Bassa 2.1

The HFS and HFS+ (hfsplus) modules in Linux 2.6 allow attackers to cause a denial of service (oops) by using hfsplus to mount a filesystem that is not hfsplus.

linux linux_kernel
0.00EPSS
CVE-2004-0181
Bassa 2.1

The JFS file system code in Linux 2.4.x has an information leak in which in-memory data is written to the device for the JFS file system, which allows local users to obtain sensitive information by reading the raw device.

linux linux_kernel
0.00EPSS
CVE-2001-1391
Media 5.5

Off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.

linux linux_kernel
0.00EPSS
CVE-2025-39702
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.

debian debian_linux · linux linux_kernel
0.00EPSS