imPC@ndo EN

Vulnerabilità Linux

14.796 CVE

CVE-2026-45843
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed packet length slhc_uncompress() parses a VJ-compressed TCP header by advancing a pointer through the packet via decode() and pull16(). Neith…

linux linux_kernel
0.00EPSS
CVE-2024-35789
Alta 8.0

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes When moving a station out of a VLAN and deleting the VLAN afterwards, the fast_rx entry still holds a pointer to the VLAN's…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-33203
Media 6.4

The Linux kernel before 6.2.9 has a race condition and resultant use-after-free in drivers/net/ethernet/qualcomm/emac/emac.c if a physically proximate attacker unplugs an emac based device.

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2023-31081
Media 5.5

An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vidtv_mux_stop_thread. In vidtv_stop_streaming, after dvb->mux=NULL occurs, it executes vidtv_mux_stop_thread(dvb->mux).

linux linux_kernel
0.00EPSS
CVE-2022-0500
Alta 7.8

A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the sy…

fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · e altri 6
0.00EPSS
CVE-2015-4176
Media 5.5

fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by leveraging user-namespace root access for deletion of a file or directory.

linux linux_kernel
0.00EPSS
CVE-2013-4343
Media 6.9

Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TUNSETIFF ioctl call.

canonical ubuntu_linux · linux linux_kernel
0.00EPSS
CVE-2026-53002
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: remove sprintf usage Replace it with scnprintf, the buffer sizes are expected to be large enough to hold the result, no need for snprintf+overflow check. Increase buff…

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2026-43239
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races in ->query_interfaces() It was possible for two query interface works to be concurrently trying to update the interfaces. Prevent this by checking and updating if…

linux linux_kernel
0.00EPSS
CVE-2023-53192
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix nexthop hash size The nexthop code expects a 31 bit hash, such as what is returned by fib_multipath_hash() and rt6_multipath_hash(). Passing the 32 bit hash returned by skb_get_ha…

linux linux_kernel
0.00EPSS
CVE-2025-22110
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: Initialize ctx to avoid memory allocation error It is possible that ctx in nfqnl_build_packet_message() could be used before it is properly initialize, which is o…

linux linux_kernel
0.00EPSS
CVE-2025-21868
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: allow small head cache usage with large MAX_SKB_FRAGS values Sabrina reported the following splat: WARNING: CPU: 0 PID: 1 at net/core/dev.c:6935 netif_napi_add_weight_locked+0x8f2/…

linux linux_kernel
0.00EPSS
CVE-2021-3760
Alta 7.8

A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability.

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp h300e_firmware · e altri 7
0.00EPSS
CVE-2012-6701
Alta 7.8

Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large AIO iovec.

linux linux_kernel
0.00EPSS
CVE-2013-3076
Media 4.9

The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg functi…

linux linux_kernel
0.00EPSS
CVE-2012-6542
Bassa 1.9

The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an…

linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2012-6541
Bassa 1.9

The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

linux linux_kernel
0.00EPSS
CVE-2011-2494
Bassa 2.1

kernel/taskstats.c in the Linux kernel before 3.1 allows local users to obtain sensitive I/O statistics by sending taskstats commands to a netlink socket, as demonstrated by discovering the length of another user's password.

linux linux_kernel
0.00EPSS
CVE-2011-2492
Bassa 1.9

The bluetooth subsystem in the Linux kernel before 3.0-rc4 does not properly initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel memory via a crafted getsockopt system call, related to (1) the l2…

linux linux_kernel · redhat enterprise_linux_aus · redhat enterprise_linux_desktop · redhat enterprise_linux_eus · e altri 2
0.00EPSS
CVE-2026-53248
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: net: airoha: Fix use-after-free in metadata dst teardown airoha_metadata_dst_free() runs metadata_dst_free() which frees the metadata_dst with kfree() immediately, bypassing the RCU grace pe…

linux linux_kernel
0.00EPSS
CVE-2026-43345
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix event ring index not programmed for IPA v5.0+ For IPA v5.0+, the event ring index field moved from CH_C_CNTXT_0 to CH_C_CNTXT_1. The v5.0 register definition intended to define…

linux linux_kernel
0.00EPSS
CVE-2025-38405
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix memory leak of bio integrity If nvmet receives commands with metadata there is a continuous memory leak of kmalloc-128 slab or more precisely bio->bi_integrity. Since commit bf4c…

linux linux_kernel
0.00EPSS
CVE-2025-21967
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in ksmbd_free_work_struct ->interim_entry of ksmbd_work could be deleted after oplock is freed. We don't need to manage it with linked list. The interim request cou…

linux linux_kernel
0.00EPSS
CVE-2024-27416
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-47090
Media 5.5

In the Linux kernel, the following vulnerability has been resolved: mm/hwpoison: clear MF_COUNT_INCREASED before retrying get_any_page() Hulk Robot reported a panic in put_page_testzero() when testing madvise() with MADV_SOFT_OFFLINE. The BUG() is triggered…

linux linux_kernel
0.00EPSS