imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2017-0564
Alta 7.8

An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compro…

linux linux_kernel
0.04EPSS
CVE-2013-2017
Alta 7.8

The veth (aka virtual Ethernet) driver in the Linux kernel before 2.6.34 does not properly manage skbs during congestion, which allows remote attackers to cause a denial of service (system crash) by leveraging lack of skb consumption in conjunction with a doub…

linux linux_kernel
0.04EPSS
CVE-2013-1763
Alta 7.2

Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges via a large family value in a Netlink message.

linux linux_kernel
0.04EPSS
CVE-2016-4580
Alta 7.5

The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory via an X.25 Call Request.

canonical ubuntu_linux · linux linux_kernel
0.04EPSS
CVE-2011-4913
Alta 7.8

The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corr…

linux linux_kernel · novell suse_linux_enterprise_server
0.04EPSS
CVE-2018-20784
Critica 9.8

In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.

canonical ubuntu_linux · linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_for_real_time
0.04EPSS
CVE-2004-0883
Media 6.4

Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to t…

linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_desktop · redhat fedora_core · e altri 4
0.04EPSS
CVE-2019-19768
Alta 7.5

In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace.c (which is used to fill out a blk_io_trace structure and place it in a per-cpu sub-buffer).

linux linux_kernel
0.04EPSS
CVE-2014-3535
Alta 7.8

include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) by sending inva…

linux linux_kernel
0.04EPSS
CVE-2019-19044
Alta 7.5

Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762…

broadcom brocade_fabric_operating_system_firmware · canonical ubuntu_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 12
0.04EPSS
CVE-2013-4350
Media 5.0

The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive information by sniff…

linux linux_kernel
0.04EPSS
CVE-2018-1000026
Alta 7.7

Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exp…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · redhat enterprise_linux · e altri 3
0.04EPSS
CVE-2017-16912
Media 5.9

The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a denial of service (out-of-bounds read) via a specially crafted USB over IP packet.

linux linux_kernel
0.04EPSS
CVE-2017-15126
Alta 8.1

A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly can lead to a situation where a fork event will be removed f…

linux linux_kernel
0.04EPSS
CVE-2023-32252
Alta 7.5

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker ca…

linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · netapp h410s_firmware · e altri 2
0.04EPSS
CVE-2023-32248
Alta 7.5

A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_TREE_CONNECT and SMB2_QUERY_INFO commands. The issue results from the lack of proper validation of a pointer prior to ac…

linux linux_kernel · netapp h300s · netapp h410c · netapp h410s · e altri 2
0.04EPSS
CVE-2010-2248
Alta 7.8

fs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before 2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via an SMB response packet with an invalid CountHigh value, as demonstrated by a response from an OS/2 server, relat…

linux linux_kernel
0.04EPSS
CVE-2011-0709
Alta 7.5

The br_mdb_ip_get function in net/bridge/br_multicast.c in the Linux kernel before 2.6.35-rc5 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an IGMP packet, related to lack of a multicast table.

linux linux_kernel
0.04EPSS
CVE-2022-3435
Media 4.3

A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the at…

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.04EPSS
CVE-2019-19075
Alta 7.5

A memory leak in the ca8210_probe() function in drivers/net/ieee802154/ca8210.c in the Linux kernel before 5.3.8 allows attackers to cause a denial of service (memory consumption) by triggering ca8210_get_platform_data() failures, aka CID-6402939ec86e.

canonical ubuntu_linux · linux linux_kernel
0.04EPSS
CVE-2005-2458
Media 5.0

inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables".

linux linux_kernel
0.04EPSS
CVE-2017-16913
Media 5.9

The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 when handling CMD_SUBMIT packets allows attackers to cause a denial of service (arbitrary memory allocation) via a specially craf…

linux linux_kernel
0.04EPSS
CVE-2019-15538
Alta 7.5

An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 14
0.04EPSS
CVE-2017-5970
Alta 7.5

The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP optio…

linux linux_kernel
0.04EPSS
CVE-2005-2872
Media 5.0

The ipt_recent kernel module (ipt_recent.c) in Linux kernel before 2.6.12, when running on 64-bit processors such as AMD64, allows remote attackers to cause a denial of service (kernel panic) via certain attacks such as SSH brute force, which leads to memset c…

linux linux_kernel
0.04EPSS