imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2008-5713
Media 4.9

The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocatio…

linux linux_kernel
0.01EPSS
CVE-2017-0650
Media 4.7

An information disclosure vulnerability in the Synaptics touchscreen driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Low because it first requires compromising a privileged process. Prod…

linux linux_kernel
0.01EPSS
CVE-2016-6757
Media 4.7

An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires co…

linux linux_kernel
0.01EPSS
CVE-2016-6756
Media 4.7

An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires co…

linux linux_kernel
0.01EPSS
CVE-2009-2767
Alta 7.2

The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW clock_nanosleep call that triggers a NULL pointer derefer…

linux kernel · linux linux_kernel
0.01EPSS
CVE-2024-38565
Media 5.5

In the Linux kernel, the following vulnerability has been resolved: wifi: ar5523: enable proper endpoint verification Syzkaller reports [1] hitting a warning about an endpoint in use not having an expected type to it. Fix the issue by checking for the exist…

linux linux_kernel
0.01EPSS
CVE-2024-50095
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Improve handling of timed out WRs of mad agent Current timeout handler of mad agent acquires/releases mad_agent_priv lock for every timed out WRs. This causes heavy locking content…

linux linux_kernel
0.01EPSS
CVE-2021-46955
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with KASAN, it's possible to see the following splat while testing fragmentation of IPv4 p…

linux linux_kernel
0.01EPSS
CVE-2021-47482
Media 5.3

In the Linux kernel, the following vulnerability has been resolved: net: batman-adv: fix error handling Syzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was in wrong error handling in batadv_mesh_init(). Before this patch batadv_mesh_ini…

linux linux_kernel
0.01EPSS
CVE-2024-26800
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait until all async decrypti…

linux linux_kernel
0.01EPSS
CVE-2016-2068
Alta 7.8

The MSM QDSP6 audio driver (aka sound driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (integer overflow, a…

google android · linux linux_kernel
0.01EPSS
CVE-2021-47162
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: tipc: skb_linearize the head skb when reassembling msgs It's not a good idea to append the frag skb to a skb's frag_list if the frag_list already has skbs from elsewhere, such as this skb wa…

linux linux_kernel
0.01EPSS
CVE-2023-52618
Media 5.3

In the Linux kernel, the following vulnerability has been resolved: block/rnbd-srv: Check for unlikely string overflow Since "dev_search_path" can technically be as large as PATH_MAX, there was a risk of truncation when copying it and a second string into "f…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2019-19524
Media 4.6

In the Linux kernel before 5.3.12, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/input/ff-memless.c driver, aka CID-fa3a5a1880c9.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2014-8559
Media 5.5

The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.

canonical ubuntu_linux · linux linux_kernel · novell suse_linux_enterprise_desktop · novell suse_linux_enterprise_server · e altri 7
0.01EPSS
CVE-2024-44984
Critica 10.0

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix double DMA unmapping for XDP_REDIRECT Remove the dma_unmap_page_attrs() call in the driver's XDP_REDIRECT code path. This should have been removed when we let the page pool han…

linux linux_kernel
0.01EPSS
CVE-2022-48655
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Harden accesses to the reset domains Accessing reset domains descriptors by the index upon the SCMI drivers requests through the SCMI reset operations interface can poten…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2024-40937
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: gve: Clear napi->skb before dev_kfree_skb_any() gve_rx_free_skb incorrectly leaves napi->skb referencing an skb after it is freed with dev_kfree_skb_any(). This can result in a subsequent ca…

linux linux_kernel
0.01EPSS
CVE-2021-46999
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: sctp: do asoc update earlier in sctp_sf_do_dupcook_a There's a panic that occurs in a few of envs, the call trace is as below: [] general protection fault, ... 0x29acd70f1000a: 0000 [#1] …

linux linux_kernel
0.01EPSS
CVE-2019-18660
Media 4.7

The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · opensuse leap · e altri 1
0.01EPSS
CVE-2024-26851
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: Add protection for bmp length out of range UBSAN load reports an exception of BRK#5515 SHIFT_ISSUE:Bitwise shifts that are out of bounds for their data type. v…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2024-26845
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Add TMF to tmr_list handling An abort that is responded to by iSCSI itself is added to tmr_list but does not go to target core. A LUN_RESET that goes through tmr_list tak…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-1999-0460
Bassa 2.1

Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.

linux linux_kernel
0.01EPSS
CVE-1999-0451
Bassa 2.1

Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.

linux linux_kernel
0.01EPSS
CVE-2021-47354
Alta 7.1

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing it to avoid data corruptions.

linux linux_kernel
0.01EPSS