imPC@ndo EN

Vulnerabilità Linux

14.802 CVE

CVE-2020-36310
Media 5.5

An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2019-18808
Media 5.5

A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse leap
0.00EPSS
CVE-2017-18200
Media 5.5

The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demonstrated by fstrim.

linux linux_kernel
0.00EPSS
CVE-2017-8106
Media 5.5

The handle_invept function in arch/x86/kvm/vmx.c in the Linux kernel 3.12 through 3.15 allows privileged KVM guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a single-context INVEPT instruction with a NULL EPT pointe…

linux linux_kernel
0.00EPSS
CVE-2012-2372
Media 4.4

The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with …

linux linux_kernel
0.00EPSS
CVE-2025-38617
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and packet_notifier() When packet_set_ring() releases po->bind_lock, another thread can run packet_notifier() and process an NETDEV_UP event. Thi…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2022-49416
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix use-after-free in chanctx code In ieee80211_vif_use_reserved_context(), when we have an old context and the new context's replace_state is set to IEEE80211_CHANCTX_REPLAC…

linux linux_kernel
0.00EPSS
CVE-2023-52886
Media 6.4

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read in sysfs.c:read_descriptors(): BUG: KASAN: slab-out-of-bounds in read_descri…

linux linux_kernel
0.00EPSS
CVE-2023-26545
Media 4.7

In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.

debian debian_linux · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · e altri 3
0.00EPSS
CVE-2022-1516
Media 5.5

A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality in the way a user terminates their session using a simulated Ethernet card and continued usage of this connection. This flaw allows a local…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-38205
Bassa 3.3

drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2020-12652
Media 4.1

The __mptctl_ioctl function in drivers/message/fusion/mptctl.c in the Linux kernel before 5.4.14 allows local users to hold an incorrect lock during the ioctl operation and trigger a race condition, i.e., a "double fetch" vulnerability, aka CID-28d76df18f0a. N…

linux linux_kernel
0.00EPSS
CVE-2019-0145
Alta 7.8

Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

intel ethernet_700_series_software · intel ethernet_controller_710-bm1_firmware · intel ethernet_controller_x710-at2_firmware · intel ethernet_controller_x710-bm2_firmware · e altri 4
0.00EPSS
CVE-2026-23139
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: update last_gc only when GC has been performed Currently last_gc is being updated everytime a new connection is tracked, that means that it is updated even if a GC w…

linux linux_kernel
0.00EPSS
CVE-2022-49160
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix crash during module load unload test During purex packet handling the driver was incorrectly freeing a pre-allocated structure. Fix this by skipping that entry. System cr…

linux linux_kernel
0.00EPSS
CVE-2024-56651
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: can: hi311x: hi3110_can_ist(): fix potential use-after-free The commit a22bd630cfff ("can: hi311x: do not report txerr and rxerr during bus-off") removed the reporting of rxerr and txerr eve…

linux linux_kernel
0.00EPSS
CVE-2024-50001
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix error path in multi-packet WQE transmit Remove the erroneous unmap in case no DMA mapping was established The multi-packet WQE transmit code attempts to obtain a DMA mapping f…

linux linux_kernel
0.00EPSS
CVE-2024-49894
Alta 7.1

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index out of bounds in degamma hardware format translation Fixes index out of bounds issue in `cm_helper_translate_curve_to_degamma_hw_format` function. The issue could …

debian debian_linux · linux linux_kernel · siemens simatic_s7-1500_tm_mfp_firmware · siemens sinec_os
0.00EPSS
CVE-2024-26798
Media 5.5

In the Linux kernel, the following vulnerability has been resolved: fbcon: always restore the old font data in fbcon_do_set_font() Commit a5a923038d70 (fbdev: fbcon: Properly revert changes when vc_resize() failed) started restoring old font data upon failur…

linux linux_kernel
0.00EPSS
CVE-2022-34495
Media 5.5

rpmsg_probe in drivers/rpmsg/virtio_rpmsg_bus.c in the Linux kernel before 5.18.4 has a double free.

linux linux_kernel
0.00EPSS
CVE-2022-1998
Alta 7.8

A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privil…

fedoraproject fedora · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · e altri 4
0.00EPSS
CVE-2013-0349
Bassa 1.9

The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCONNADD …

linux linux_kernel
0.00EPSS
CVE-2025-37952
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix UAF in __close_file_table_ids A use-after-free is possible if one thread destroys the file via __ksmbd_close_fd while another thread holds a reference to it. The existing checks o…

linux linux_kernel
0.00EPSS
CVE-2024-57997
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix channel survey memory allocation size KASAN reported a memory allocation issue in wcn->chan_survey due to incorrect size calculation. This commit uses kcalloc to allocate …

linux linux_kernel
0.00EPSS
CVE-2015-4170
Media 4.7

Race condition in the ldsem_cmpxchg function in drivers/tty/tty_ldsem.c in the Linux kernel before 3.13-rc4-next-20131218 allows local users to cause a denial of service (ldsem_down_read and ldsem_down_write deadlock) by establishing a new tty thread during sh…

linux linux_kernel · redhat enterprise_linux_compute_node_eus · redhat enterprise_linux_for_ibm_z_systems_eus · redhat enterprise_linux_for_power_big_endian_eus · e altri 2
0.00EPSS