imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2017-13694
Media 5.5

The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memor…

linux linux_kernel
0.00EPSS
CVE-2017-2647
Alta 7.8

The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_iterat…

linux linux_kernel
0.00EPSS
CVE-2010-3297
Bassa 2.1

The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRC…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 3
0.00EPSS
CVE-2009-0745
Media 4.9

The ext4_group_add function in fs/ext4/resize.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not properly initialize the group descriptor during a resize (aka resize2fs) operation, which might allow local users to cause a denial …

linux linux_kernel
0.00EPSS
CVE-2009-0031
Media 4.9

Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."

linux linux_kernel
0.00EPSS
CVE-2025-21673
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS targets before it realiz…

linux linux_kernel
0.00EPSS
CVE-2025-21663
Critica 10.0

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from device tree Nvidia's Tegra MGBE controllers require the IOMMU "Stream ID" (SID) to be written to the MGBE_WRAP_AXI_ASID0_CTRL register. T…

linux linux_kernel
0.00EPSS
CVE-2023-32820
Alta 7.5

In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue …

google android · linux linux_kernel · linuxfoundation yocto · mediatek iot_yocto
0.00EPSS
CVE-2022-4696
Alta 7.8

There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter…

linux linux_kernel
0.00EPSS
CVE-2011-4916
Media 5.5

Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*.

linux linux_kernel
0.00EPSS
CVE-2017-8072
Alta 7.8

The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 does not have the expected EIO error status for a zero-length report, which allows local users to have an unspecified impact via unknown vectors.

linux linux_kernel
0.00EPSS
CVE-2014-9730
Media 4.9

The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.

linux linux_kernel
0.00EPSS
CVE-2012-5532
Media 4.9

The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exis…

linux linux_kernel
0.00EPSS
CVE-2011-2213
Media 4.9

The inet_diag_bc_audit function in net/ipv4/inet_diag.c in the Linux kernel before 2.6.39.3 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions…

linux linux_kernel · redhat enterprise_linux_aus · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · e altri 2
0.00EPSS
CVE-2011-1013
Alta 7.2

Integer signedness error in the drm_modeset_ctl function in (1) drivers/gpu/drm/drm_irq.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.38 and (2) sys/dev/pci/drm/drm_irq.c in the kernel in OpenBSD before 4.9 allows local users…

linux linux_kernel · openbsd openbsd
0.00EPSS
CVE-2010-3861
Bassa 2.1

The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a la…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · suse linux_enterprise_desktop · e altri 2
0.00EPSS
CVE-2010-3298
Bassa 2.1

The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT i…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse opensuse · e altri 3
0.00EPSS
CVE-2010-3078
Media 5.5

The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl cal…

canonical ubuntu_linux · linux linux_kernel · opensuse opensuse · suse suse_linux_enterprise_desktop · e altri 2
0.00EPSS
CVE-2006-0558
Media 4.9

perfmon (perfmon.c) in Linux kernel on IA64 architectures allows local users to cause a denial of service (crash) by interrupting a task while another process is accessing the mm_struct, which triggers a BUG_ON action in the put_page_testzero function.

linux linux_kernel
0.00EPSS
CVE-2004-0229
Media 4.6

The framebuffer driver in Linux kernel 2.6.x does not properly use the fb_copy_cmap function, with unknown impact.

gentoo linux · linux linux_kernel
0.00EPSS
CVE-1999-1341
Media 4.6

Linux kernel before 2.3.18 or 2.2.13pre15, with SLIP and PPP options, allows local unprivileged users to forge IP packets via the TIOCSETD option on tty devices.

linux linux_kernel
0.00EPSS
CVE-2023-42754
Media 5.5

A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow…

fedoraproject fedora · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2019-19252
Alta 7.8

vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.

linux linux_kernel
0.00EPSS
CVE-2019-19055
Media 5.5

A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering nl80211hdr_put() failures, aka CID-1399c59fa929. NOTE:…

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2019-12456
Alta 7.8

An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux kernel through 5.1.5. It allows local users to cause a denial of service or possibly have unspecified other impact by changing the value of io…

linux linux_kernel
0.00EPSS