imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2009-0028
Bassa 2.1

The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new proc…

linux linux_kernel
0.01EPSS
CVE-2024-26954
Alta 8.1

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16() If ->NameOffset of smb2_create_req is smaller than Buffer offset of smb2_create_req, slab-out-of-bounds read can happen from smb2_op…

linux linux_kernel
0.01EPSS
CVE-2024-53217
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent NULL dereference in nfsd4_process_cb_update() @ses is initialized to NULL. If __nfsd4_find_backchannel() finds no available backchannel session, setup_callback_client() will tr…

linux linux_kernel
0.01EPSS
CVE-2024-26689
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This im…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2026-64268
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at sge->laddr + wqe->proc…

linux linux_kernel
0.01EPSS
CVE-2024-56644
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net/ipv6: release expired exception dst cached in socket Dst objects get leaked in ip6_negative_advice() when this function is executed for an expired IPv6 route located in the exception tab…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2023-46813
Alta 7.0

An issue was discovered in the Linux kernel before 6.5.9, exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrar…

linux linux_kernel
0.01EPSS
CVE-2019-15216
Media 4.6

An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp active_iq_unified_manager · e altri 5
0.01EPSS
CVE-2019-19319
Media 6.5

In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, …

linux linux_kernel · opensuse leap · redhat enterprise_linux
0.01EPSS
CVE-2004-0814
Bassa 1.2

Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x before 2.6.9, allow (1) local users to obtain portions of kernel data via a TIOCSETD ioctl call to a terminal interface that is being accessed by another thread, or (2) remote attackers t…

linux linux_kernel · ubuntu ubuntu_linux
0.01EPSS
CVE-2021-32399
Alta 7.0

net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.

debian debian_linux · linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · e altri 7
0.01EPSS
CVE-2026-53383
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: ksmbd: reject non-VALID session in compound request branch smb2_check_user_session() takes a shortcut for any operation that is not the first in a COMPOUND request: it reuses work->sess (the…

linux linux_kernel
0.01EPSS
CVE-2020-29371
Bassa 3.3

An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace, aka CID-bcf85fcedfdd.

linux linux_kernel
0.01EPSS
CVE-2024-26882
Alta 7.3

In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: make sure to pull inner header in ip_tunnel_rcv() Apply the same fix than ones found in : 8d975c15c0cd ("ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()") 1ca1…

linux linux_kernel
0.01EPSS
CVE-2024-42256
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry, netfs will call cifs_prepare_write() which will make cifs repick the server for the op before re…

linux linux_kernel
0.01EPSS
CVE-2024-26881
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when 1588 is received on HIP08 devices The HIP08 devices does not register the ptp devices, so the hdev->ptp is NULL, but the hardware can receive 1588 messages, …

linux linux_kernel
0.01EPSS
CVE-2021-3612
Alta 7.8

An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on t…

debian debian_linux · fedoraproject fedora · linux linux_kernel · netapp cloud_backup · e altri 13
0.01EPSS
CVE-2026-45860
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection clean up limit to 64 After the optimization to only perform one GC per jiffy, a new problem was introduced. If more than 8 new connections ar…

linux linux_kernel
0.01EPSS
CVE-2024-47695
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds In the function init_conns(), after the create_con() and create_cm() for loop if something fails. In the cleanup for loop after the …

linux linux_kernel
0.01EPSS
CVE-2024-35971
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Handle softirqs at the end of IRQ thread to fix hang The ks8851_irq() thread may call ks8851_rx_pkts() in case there are any packets in the MAC FIFO, which calls netif_rx(). Thi…

linux linux_kernel
0.01EPSS
CVE-2019-15793
Media 6.5

In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, wher…

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2021-47307
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: cifs: prevent NULL deref in cifs_compose_mount_options() The optional @ref parameter might contain an NULL node_name, so prevent dereferencing it in cifs_compose_mount_options(). Addresses-…

linux linux_kernel
0.01EPSS
CVE-2021-47267
Media 6.3

In the Linux kernel, the following vulnerability has been resolved: usb: fix various gadget panics on 10gbps cabling usb_assign_descriptors() is called with 5 parameters, the last 4 of which are the usb_descriptor_header for: full-speed (USB1.1 - 12Mbps [i…

linux linux_kernel
0.01EPSS
CVE-2023-52669
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2021-47109
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: neighbour: allow NUD_NOARP entries to be forced GCed IFF_POINTOPOINT interfaces use NUD_NOARP entries for IPv6. It's possible to fill up the neighbour table with enough entries that it will …

linux linux_kernel
0.01EPSS