imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2021-3411
Media 6.7

A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2020-29374
Bassa 3.6

An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can g…

debian debian_linux · linux linux_kernel · netapp 500f_firmware · netapp a250_firmware · e altri 4
0.00EPSS
CVE-2016-10907
Alta 7.8

An issue was discovered in drivers/iio/dac/ad5755.c in the Linux kernel before 4.8.6. There is an out of bounds write in the function ad5755_parse_dt.

linux linux_kernel
0.00EPSS
CVE-2012-6546
Bassa 1.9

The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2013-0290
Media 4.9

The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted applica…

linux linux_kernel
0.00EPSS
CVE-2010-4346
Bassa 2.1

The install_special_mapping function in mm/mmap.c in the Linux kernel before 2.6.37-rc6 does not make an expected security_file_mmap function call, which allows local users to bypass intended mmap_min_addr restrictions and possibly conduct NULL pointer derefer…

linux linux_kernel
0.00EPSS
CVE-2006-4813
Bassa 2.1

The __block_prepare_write function in fs/buffer.c for Linux kernel 2.6.x before 2.6.13 does not properly clear buffers during certain error conditions, which allows local users to read portions of files that have been unlinked.

linux linux_kernel
0.00EPSS
CVE-2006-0038
Media 6.9

Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function.

linux linux_kernel
0.00EPSS
CVE-2005-3660
Media 4.9

Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service (memory exhaustion and panic) by creating a large number of connected file descriptors or socketpairs and setting a large data transfer buffer, then preventing Linux from being able to fini…

linux linux_kernel
0.00EPSS
CVE-2004-0997
Media 4.6

Unspecified vulnerability in the ptrace MIPS assembly code in Linux kernel 2.4 before 2.4.17 allows local users to gain privileges via unknown vectors.

linux linux_kernel
0.00EPSS
CVE-2024-46690
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd4_deleg_getattr_conflict in presence of third party lease It is not safe to dereference fl->c.flc_owner without first confirming fl->fl_lmops is the expected manager. nfsd4_de…

linux linux_kernel
0.00EPSS
CVE-2021-20219
Media 5.5

A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In this flaw a local attacker with a normal user privilege could delay the loop (due to a changing ldata->read_head, and a missing sanity chec…

linux linux_kernel
0.00EPSS
CVE-2018-5953
Media 5.5

The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2018-12928
Media 5.5

In the Linux kernel 4.15.0, a NULL pointer dereference was discovered in hfs_ext_read_extent in hfs.ko. This can occur during a mount of a crafted hfs filesystem.

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2010-5321
Media 4.3

Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6.x through 4.x allows local users to cause a denial of service (memory consumption) by leveraging /dev/video access for a series of mmap calls that require new …

linux linux_kernel
0.00EPSS
CVE-2017-8067
Alta 7.8

drivers/char/virtio_console.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified ot…

linux linux_kernel
0.00EPSS
CVE-2017-2596
Media 6.5

The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of…

linux linux_kernel
0.00EPSS
CVE-2016-8441
Alta 7.8

Possible buffer overflow in the hypervisor. Inappropriate usage of a static array could lead to a buffer overrun. Product: Android. Versions: Kernel 3.18. Android ID: A-31625904. References: QC-CR#1027769.

linux linux_kernel
0.00EPSS
CVE-2014-2673
Media 4.7

The arch_dup_task_struct function in the Transactional Memory (TM) implementation in arch/powerpc/kernel/process.c in the Linux kernel before 3.13.7 on the powerpc platform does not properly interact with the clone and fork system calls, which allows local use…

linux linux_kernel
0.00EPSS
CVE-2009-0675
Bassa 2.1

The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the driver …

linux linux_kernel
0.00EPSS
CVE-2005-0136
Bassa 2.1

The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.

linux linux_kernel
0.00EPSS
CVE-2002-1571
Bassa 2.1

The linux 2.4 kernel before 2.4.19 assumes that the fninit instruction clears all registers, which could lead to an information leak on processors that do not clear all relevant SSE registers.

linux linux_kernel
0.00EPSS
CVE-2025-38001
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice Savino says: "We are writing to report that this recent patch (141d34391abbb315d68556b7c67ad97885407547) [1] …

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2024-40941
Alta 8.1

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't read past the mfuart notifcation In case the firmware sends a notification that claims it has more data than it has, we will read past that was allocated for the no…

linux linux_kernel
0.00EPSS
CVE-2021-4149
Media 5.5

A vulnerability was found in btrfs_alloc_tree_b in fs/btrfs/extent-tree.c in the Linux kernel due to an improper lock operation in btrfs. In this flaw, a user with a local privilege may cause a denial of service (DOS) due to a deadlock problem.

debian debian_linux · linux linux_kernel
0.00EPSS