imPC@ndo EN

Vulnerabilità Linux

14.781 CVE

CVE-2012-0038
Media 5.5

Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.

linux linux_kernel
0.00EPSS
CVE-2009-3612
Bassa 2.1

The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive inform…

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse opensuse · e altri 3
0.00EPSS
CVE-2024-53059
Alta 7.1

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: Fix response handling in iwl_mvm_send_recovery_cmd() 1. The size of the response packet is not validated. 2. The response buffer is not freed. Resolve these issues by sw…

linux linux_kernel
0.00EPSS
CVE-2024-46755
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id() mwifiex_get_priv_by_id() returns the priv pointer corresponding to the bss_num and bss_type, but without checking if the …

linux linux_kernel
0.00EPSS
CVE-2021-20317
Media 4.4

A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and event…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-16531
Media 6.6

drivers/usb/core/config.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to the USB_DT_INTERFACE_ASSOCIATION de…

linux linux_kernel
0.00EPSS
CVE-2017-16529
Media 6.6

The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-15537
Media 5.5

The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature, does not correctly handle attempts to set reserved bits in the xstate header via the ptrace() or rt_sigreturn…

linux linux_kernel
0.00EPSS
CVE-2015-8709
Alta 7.0

kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user namespace, waiting for a root process to enter that namespace with an unsafe uid or gid, and then using the pt…

linux linux_kernel
0.00EPSS
CVE-2009-2287
Media 4.9

The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a cra…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2008-3077
Media 4.9

arch/x86/kernel/ptrace.c in the Linux kernel before 2.6.25.10 on the x86_64 platform leaks task_struct references into the sys32_ptrace function, which allows local users to cause a denial of service (system crash) or have unspecified other impact via unknown …

linux linux_kernel
0.00EPSS
CVE-2005-3805
Media 4.9

A locking problem in POSIX timer cleanup handling on exit in Linux kernel 2.6.10 to 2.6.14, when running on SMP systems, allows local users to cause a denial of service (deadlock) involving process CPU timers.

linux linux_kernel
0.00EPSS
CVE-2005-3179
Bassa 2.1

drm.c in Linux kernel 2.6.10 to 2.6.13 creates a debug file in sysfs with world-readable and world-writable permissions, which allows local users to enable DRM debugging and obtain sensitive information.

linux linux_kernel
0.00EPSS
CVE-2005-0867
Alta 7.2

Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.

linux linux_kernel
0.00EPSS
CVE-1999-0245
Media 4.6

Some configurations of NIS+ in Linux allowed attackers to log in as the user "+".

linux linux_kernel
0.00EPSS
CVE-2026-46135
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp), but it does so witho…

linux linux_kernel
0.00EPSS
CVE-2022-50483
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: enetc: avoid buffer leaks on xdp_do_redirect() failure Before enetc_clean_rx_ring_xdp() calls xdp_do_redirect(), each software BD in the RX ring between index orig_i and i can have one …

linux linux_kernel
0.00EPSS
CVE-2024-27435
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: nvme: fix reconnection fail due to reserved tag allocation We found a issue on production environment while using NVMe over RDMA, admin_q reconnect failed forever while remote target and net…

linux linux_kernel
0.00EPSS
CVE-2023-39192
Media 6.7

A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond…

fedoraproject fedora · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2022-24448
Bassa 3.3

An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the ser…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2020-29372
Media 4.7

An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e.

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2020-11884
Alta 7.0

In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 19
0.00EPSS
CVE-2018-8043
Media 5.5

The unimac_mdio_probe function in drivers/net/phy/mdio-bcm-unimac.c in the Linux kernel through 4.15.8 does not validate certain resource availability, which allows local users to cause a denial of service (NULL pointer dereference).

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2017-17864
Bassa 3.3

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-16996
Alta 7.8

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging register truncation mishandling.

debian debian_linux · linux linux_kernel
0.00EPSS