imPC@ndo EN

Vulnerabilità Linux

14.802 CVE

CVE-2020-36312
Media 5.5

An issue was discovered in the Linux kernel before 5.8.10. virt/kvm/kvm_main.c has a kvm_io_bus_unregister_dev memory leak upon a kmalloc failure, aka CID-f65886606c2d.

linux linux_kernel
0.00EPSS
CVE-2019-20934
Media 5.3

An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free in show_numa_stats() because NUMA fault statistics are inappropriately freed, aka CID-16d51a590a8c.

linux linux_kernel
0.00EPSS
CVE-2007-3851
Media 6.0

The drm/i915 component in the Linux kernel before 2.6.22.2, when used with i965G and later chipsets, allows local users with access to an X11 session and Direct Rendering Manager (DRM) to write to arbitrary memory locations and gain privileges via a crafted ba…

linux linux_kernel
0.00EPSS
CVE-2007-3719
Bassa 2.1

The process scheduler in the Linux kernel 2.6.16 gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuse…

linux linux_kernel
0.00EPSS
CVE-2025-37840
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: brcmnand: fix PM resume warning Fixed warning on PM resume as shown below caused due to uninitialized struct nand_operation that checks chip select field : WARN_ON(op->cs >= na…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2025-37839
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: jbd2: remove wrong sb->s_sequence check Journal emptiness is not determined by sb->s_sequence == 0 but rather by sb->s_start == 0 (which is set a few lines above). Furthermore 0 is a valid t…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-53034
Alta 7.1

In the Linux kernel, the following vulnerability has been resolved: ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and size. This would make xlate_pos negative. [ …

linux linux_kernel
0.00EPSS
CVE-2024-27024
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: net/rds: fix WARNING in rds_conn_connect_if_down If connection isn't established yet, get_mr() will fail, trigger connection after get_mr().

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2024-26922
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more clearly Verify the parameters of amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.00EPSS
CVE-2024-26773
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() Determine if the group block bitmap is corrupted before using ac_b_ex in ext4_mb_try_best_found() to avoid allo…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-6040
Alta 7.8

An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) value…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2023-6679
Media 5.5

A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.

fedoraproject fedora · linux linux_kernel · redhat enterprise_linux
0.00EPSS
CVE-2023-23454
Media 5.5

cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid class…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2021-33655
Media 6.7

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2017-18249
Alta 7.0

The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent threads.

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2026-31607
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT response, usbip_pack_ret_submit() unconditionally overwrites urb->number_of_packets fr…

linux linux_kernel
0.00EPSS
CVE-2025-38209
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: remove tag set when second admin queue config fails Commit 104d0e2f6222 ("nvme-fabrics: reset admin connection for secure concatenation") modified nvme_tcp_setup_ctrl() to call nvm…

linux linux_kernel
0.00EPSS
CVE-2022-2961
Alta 7.0

A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate th…

fedoraproject fedora · linux linux_kernel · netapp h300s_firmware · netapp h410c_firmware · e altri 3
0.00EPSS
CVE-2020-10781
Media 5.5

A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/ directory. This read allocates kernel me…

debian debian_linux · linux linux_kernel
0.00EPSS
CVE-2007-3720
Bassa 2.1

The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result …

linux linux_kernel
0.00EPSS
CVE-1999-0782
Bassa 2.1

KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.

freebsd freebsd · kde kde · linux linux_kernel
0.00EPSS
CVE-2025-71068
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: svcrdma: bound check rq_pages index in inline path svc_rdma_copy_inline_range indexed rqstp->rq_pages[rc_curpage] without verifying rc_curpage stays within the allocated page array. Add guar…

linux linux_kernel
0.00EPSS
CVE-2024-56653
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: avoid UAF in btmtk_process_coredump hci_devcd_append may lead to the release of the skb, so it cannot be accessed once it is called. ======================================…

linux linux_kernel
0.00EPSS
CVE-2024-53241
Media 5.5

In the Linux kernel, the following vulnerability has been resolved: x86/xen: don't do PV iret hypercall through hypercall page Instead of jumping to the Xen hypercall page for doing the iret hypercall, directly code the required sequence in xen-asm.S. This …

linux linux_kernel
0.00EPSS
CVE-2024-41038
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Prevent buffer overrun when processing V2 alg headers Check that all fields of a V2 algorithm header fit into the available firmware data buffer. The wmfw V2 format introd…

linux linux_kernel
0.00EPSS