imPC@ndo EN

Vulnerabilità Linux

14.796 CVE

CVE-2013-3231
Media 4.7

The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.

linux linux_kernel
0.00EPSS
CVE-2013-2636
Bassa 1.9

net/bridge/br_mdb.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.

linux linux_kernel
0.00EPSS
CVE-2012-6543
Bassa 1.9

The l2tp_ip6_getname function in net/l2tp/l2tp_ip6.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

linux linux_kernel
0.00EPSS
CVE-2010-1083
Media 4.7

The processcompl_compat function in drivers/usb/core/devio.c in Linux kernel 2.6.x through 2.6.32, and possibly other versions, does not clear the transfer buffer before returning to userspace when a USB command fails, which might make it easier for physically…

linux linux_kernel
0.00EPSS
CVE-2009-4138
Media 4.7

drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl asso…

linux linux_kernel
0.00EPSS
CVE-2008-3247
Alta 7.2

The LDT implementation in the Linux kernel 2.6.25.x before 2.6.25.11 on x86_64 platforms uses an incorrect size for ldt_desc, which allows local users to cause a denial of service (system crash) or possibly gain privileges via unspecified vectors.

linux linux_kernel
0.00EPSS
CVE-2005-0178
Media 6.2

Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.

linux linux_kernel · netkit linux_netkit · vserver linux-vserver
0.00EPSS
CVE-2024-44988
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Fix out-of-bound access If an ATU violation was caused by a CPU Load operation, the SPID could be larger than DSA_MAX_PORTS (the size of mv88e6xxx_chip.ports[] array).

linux linux_kernel
0.00EPSS
CVE-2023-31082
Media 5.5

An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel. Note: This has been disputed by 3rd parties as not a valid vulnerability.

linux linux_kernel
0.00EPSS
CVE-2020-29368
Alta 7.0

An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1.

linux linux_kernel · netapp cloud_backup · netapp element_software · netapp h410c_firmware · e altri 3
0.00EPSS
CVE-2018-16882
Alta 8.8

A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_…

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2014-3917
Bassa 3.3

kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value o…

linux linux_kernel · redhat enterprise_linux · redhat enterprise_mrg · suse linux_enterprise_desktop
0.00EPSS
CVE-2026-52960
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: ceph: put folios not suitable for writeback The batch holds references to the folios (see `filemap_get_folios`, `folio_batch_release`), so we need to `folio_put` the folios we remove. Teste…

linux linux_kernel
0.00EPSS
CVE-2026-52956
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() In __ceph_x_decrypt(), a part of the buffer p is interpreted as a ceph_x_encrypt_header, and the magic field of this struct …

linux linux_kernel
0.00EPSS
CVE-2025-37750
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in decryption with multichannel After commit f7025d861694 ("smb: client: allocate crypto only for primary server") and commit b0abcd65ec54 ("smb: client: fix UAF in asyn…

linux linux_kernel
0.00EPSS
CVE-2025-21890
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: idpf: fix checksums set in idpf_rx_rsc() idpf_rx_rsc() uses skb_transport_offset(skb) while the transport header is not set yet. This triggers the following warning for CONFIG_DEBUG_NET=y b…

linux linux_kernel
0.00EPSS
CVE-2022-28390
Alta 7.8

ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp hci_baseboard_management_controller
0.00EPSS
CVE-2020-10690
Media 6.5

There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. …

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 18
0.00EPSS
CVE-2017-13686
Alta 7.8

net/ipv4/route.c in the Linux kernel 4.13-rc1 through 4.13-rc6 is too late to check for a NULL fi field when RTM_F_FIB_MATCH is set, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via …

linux linux_kernel
0.00EPSS
CVE-2008-7316
Media 5.5

mm/filemap.c in the Linux kernel before 2.6.25 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers an iovec of zero length, followed by a page fault for an iovec of nonzero length.

linux linux_kernel
0.00EPSS
CVE-2013-2148
Bassa 2.1

The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on the fan…

linux linux_kernel
0.00EPSS
CVE-2012-6540
Bassa 1.9

The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 3.6 does not initialize a certain structure for IP_VS_SO_GET_TIMEOUT commands, which allows local users to obtain sensitive information from kernel stack memory via a cr…

linux linux_kernel
0.00EPSS
CVE-2012-6539
Bassa 1.9

The dev_ifconf function in net/socket.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

linux linux_kernel
0.00EPSS
CVE-2026-43055
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: scsi: target: file: Use kzalloc_flex for aio_cmd The target_core_file doesn't initialize the aio_cmd->iocb for the ki_write_stream. When a write command fd_execute_rw_aio() is executed, we m…

linux linux_kernel
0.00EPSS
CVE-2025-38574
Alta 8.6

In the Linux kernel, the following vulnerability has been resolved: pptp: ensure minimal skb length in pptp_xmit() Commit aabc6596ffb3 ("net: ppp: Add bound checking for skb data on ppp_sync_txmung") fixed ppp_sync_txmunge() We need a similar fix in pptp_xm…

debian debian_linux · linux linux_kernel
0.00EPSS