imPC@ndo EN

Vulnerabilità Linux

14.796 CVE

CVE-2012-5517
Media 4.0

The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory…

linux linux_kernel
0.00EPSS
CVE-2011-0999
Media 4.9

mm/huge_memory.c in the Linux kernel before 2.6.38-rc5 does not prevent creation of a transparent huge page (THP) during the existence of a temporary stack for an exec system call, which allows local users to cause a denial of service (memory consumption) or p…

linux linux_kernel
0.00EPSS
CVE-2010-3877
Bassa 1.9

The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2010-4083
Bassa 1.9

The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) IPC_INFO, (2) SEM_INFO, (3) IPC_STAT…

debian debian_linux · linux linux_kernel · opensuse opensuse · suse linux_enterprise_desktop · e altri 3
0.00EPSS
CVE-2010-4075
Bassa 1.9

The uart_get_count function in drivers/serial/serial_core.c in the Linux kernel before 2.6.37-rc1 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCG…

linux linux_kernel
0.00EPSS
CVE-2010-0622
Bassa 2.1

The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecif…

linux linux_kernel
0.00EPSS
CVE-2008-2372
Media 4.9

The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function, which lacks a ZERO_PAGE optimization and results in allocation of "useless newly…

linux linux_kernel
0.00EPSS
CVE-2004-1144
Alta 7.2

Unknown vulnerability in the 32bit emulation code in Linux 2.4 on AMD64 systems allows local users to gain privileges.

linux linux_kernel
0.00EPSS
CVE-2024-56749
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: dlm: fix dlm_recover_members refcount on error If dlm_recover_members() fails we don't drop the references of the previous created root_list that holds and keep all rsbs alive during the rec…

linux linux_kernel
0.00EPSS
CVE-2023-26544
Alta 7.8

In the Linux kernel 6.0.8, there is a use-after-free in run_unpack in fs/ntfs3/run.c, related to a difference between NTFS sector size and media sector size.

linux linux_kernel
0.00EPSS
CVE-2019-12817
Alta 7.0

arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc syste…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 5
0.00EPSS
CVE-2017-18257
Media 5.5

The __get_data_block function in fs/f2fs/data.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow and loop) via crafted use of the open and fallocate system calls with an FS_IOC_FIEMAP ioctl.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-16530
Media 6.6

The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to drivers/usb/storage/uas-detect.h and drivers/u…

linux linux_kernel
0.00EPSS
CVE-2015-8844
Media 5.5

The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the S and T bits set, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.

linux linux_kernel
0.00EPSS
CVE-2013-2546
Bassa 2.1

The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN ca…

linux linux_kernel · redhat enterprise_mrg
0.00EPSS
CVE-2010-4650
Media 4.6

Buffer overflow in the fuse_do_ioctl function in fs/fuse/file.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging the ability to operate a CUSE server.

linux linux_kernel
0.00EPSS
CVE-2011-1044
Bassa 2.1

The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors that cau…

linux linux_kernel · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · redhat enterprise_linux_server · e altri 2
0.00EPSS
CVE-2026-31631
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix buffer overread in rxgk_do_verify_authenticator() Fix rxgk_do_verify_authenticator() to check the buffer size before checking the nonce.

linux linux_kernel
0.00EPSS
CVE-2024-27058
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: tmpfs: fix race on handling dquot rbtree A syzkaller reproducer found a race while attempting to remove dquot information from the rb tree. Fetching the rb_tree root node must also be prote…

linux linux_kernel
0.00EPSS
CVE-2022-0382
Media 5.5

An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way a user sends a TIPC datagram to one or more destinations. This flaw allows a local user to read some kernel memory. This issue is limited t…

linux linux_kernel
0.00EPSS
CVE-2021-28971
Media 5.5

In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b…

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp aff_500f_firmware · e altri 3
0.00EPSS
CVE-2020-25641
Media 5.5

A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local atta…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · opensuse leap · e altri 1
0.00EPSS
CVE-2018-11506
Alta 7.8

The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CD…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-6951
Media 5.5

The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.

linux linux_kernel
0.00EPSS
CVE-2016-6327
Media 5.5

drivers/infiniband/ulp/srpt/ib_srpt.c in the Linux kernel before 4.5.1 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an ABORT_TASK command to abort a device write operation.

linux linux_kernel
0.00EPSS