imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2026-31635
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix oversized RESPONSE authenticator length check rxgk_verify_response() decodes auth_len from the packet and is supposed to verify that it fits in the remaining bytes. The existing c…

linux linux_kernel
0.01EPSS
CVE-2022-49330
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: tcp: fix tcp_mtup_probe_success vs wrong snd_cwnd syzbot got a new report [1] finally pointing to a very old bug, added in initial support for MTU probing. tcp_mtu_probe() has checks about …

linux linux_kernel
0.01EPSS
CVE-2019-13631
Media 6.8

In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation of debugging messages.

linux linux_kernel
0.01EPSS
CVE-2014-0077
Media 5.5

drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host OS crash) or possibly gain privileges o…

linux linux_kernel
0.01EPSS
CVE-2010-2963
Media 6.2

drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory l…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 3
0.01EPSS
CVE-2024-38544
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt In rxe_comp_queue_pkt() an incoming response packet skb is enqueued to the resp_pkts queue and then a decision is made whether to run the comple…

linux linux_kernel
0.01EPSS
CVE-2023-52696
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_powercap_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2022-1679
Alta 7.8

A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privile…

debian debian_linux · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · e altri 6
0.01EPSS
CVE-2023-52511
Media 5.3

In the Linux kernel, the following vulnerability has been resolved: spi: sun6i: reduce DMA RX transfer width to single byte Through empirical testing it has been determined that sometimes RX SPI transfers with DMA enabled return corrupted data. This is down …

linux linux_kernel
0.01EPSS
CVE-2024-43847
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix invalid memory access while processing fragmented packets The monitor ring and the reo reinject ring share the same ring mask index. When the driver receives an interrupt f…

linux linux_kernel
0.01EPSS
CVE-2004-1073
Bassa 2.1

The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.

linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_desktop · redhat fedora_core · e altri 4
0.01EPSS
CVE-2022-49561
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set skb->_nfct to the already-confirmed entry. This wasn't foun…

linux linux_kernel
0.01EPSS
CVE-2024-24860
Media 4.6

A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly leading to a kernel panic or denial of service issue.

linux linux_kernel
0.01EPSS
CVE-2019-12881
Alta 7.8

i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact via crafted ioctl ca…

linux linux_kernel
0.01EPSS
CVE-2019-7221
Alta 7.8

The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel · e altri 11
0.01EPSS
CVE-2021-47347
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: wl1251: Fix possible buffer overflow in wl1251_cmd_scan Function wl1251_cmd_scan calls memcpy without checking the length. Harden by checking the length is within the maximum allowed size.

linux linux_kernel
0.01EPSS
CVE-2011-1479
Media 4.7

Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denial of service (system crash) via vectors involving failed attempts to create files. NOTE: this vulnerability exists because of an incorrect …

linux linux_kernel
0.01EPSS
CVE-2020-12464
Media 6.7

usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925.

linux linux_kernel · netapp active_iq_unified_manager · netapp aff_a700s · netapp cloud_backup · e altri 6
0.01EPSS
CVE-2010-3850
Bassa 2.1

The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl call.…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · suse linux_enterprise_desktop · e altri 3
0.01EPSS
CVE-2004-0497
Bassa 2.1

Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.

conectiva linux · gentoo linux · linux linux_kernel · mandrakesoft mandrake_linux · e altri 5
0.01EPSS
CVE-2024-41048
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: skmsg: Skip zero length skb in sk_msg_recvmsg When running BPF selftests (./test_progs -t sockmap_basic) on a Loongarch platform, the following kernel panic occurs: [...] Oops[#1]: CP…

linux linux_kernel
0.01EPSS
CVE-2017-7374
Alta 7.8

Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing…

linux linux_kernel
0.01EPSS
CVE-2022-30594
Alta 7.8

The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.

debian debian_linux · linux linux_kernel · netapp 8300_firmware · netapp 8700_firmware · e altri 10
0.01EPSS
CVE-2023-52738
Media 5.3

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/fence: Fix oops due to non-matching drm_sched init/fini Currently amdgpu calls drm_sched_fini() from the fence driver sw fini routine - such function is expected to be called only…

linux linux_kernel
0.01EPSS
CVE-2016-2186
Media 4.6

The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descrip…

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_debuginfo · novell suse_linux_enterprise_desktop · e altri 6
0.01EPSS