imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2023-0461
Alta 7.8

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS or CONFIG_XFRM_ESPINTCP has to be configured, but the operation does not r…

linux linux_kernel
0.01EPSS
CVE-2020-12769
Media 5.5

An issue was discovered in the Linux kernel before 5.4.17. drivers/spi/spi-dw.c allows attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one, aka CID-19b61392c5a8.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · netapp a700s_firmware · e altri 19
0.01EPSS
CVE-2006-2629
Media 4.0

Race condition in Linux kernel 2.6.15 to 2.6.17, when running on SMP platforms, allows local users to cause a denial of service (crash) by creating and exiting a large number of tasks, then accessing the /proc entry of a task that is exiting, which causes memo…

linux linux_kernel
0.01EPSS
CVE-2025-22040
Alta 8.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix session use-after-free in multichannel connection There is a race condition between session setup and ksmbd_sessions_deregister. The session can be freed before the connection is …

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2024-38616
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning The carl9170_tx_release() function sometimes triggers a fortified-memset warning in my randconfig builds: In file included from include/linux…

linux linux_kernel
0.01EPSS
CVE-2022-3113
Media 5.5

An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference.

linux linux_kernel
0.01EPSS
CVE-2019-8912
Alta 7.8

In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.

canonical ubuntu_linux · linux linux_kernel · opensuse leap · redhat enterprise_linux
0.01EPSS
CVE-2022-49075
Alta 8.1

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix qgroup reserve overflow the qgroup limit We use extent_changeset->bytes_changed in qgroup_reserve_data() to record how many bytes we set for EXTENT_QGROUP_RESERVED state. Currentl…

linux linux_kernel
0.01EPSS
CVE-2024-26755
Media 5.3

In the Linux kernel, the following vulnerability has been resolved: md: Don't suspend the array for interrupted reshape md_start_sync() will suspend the array if there are spares that can be added or removed from conf, however, if reshape is still in progres…

linux linux_kernel
0.01EPSS
CVE-2014-4027
Bassa 2.3

The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access t…

canonical ubuntu_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · e altri 22
0.01EPSS
CVE-2014-3145
Media 4.9

The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and syste…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · oracle linux
0.01EPSS
CVE-2014-1446
Bassa 1.9

The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an…

linux linux_kernel
0.01EPSS
CVE-2022-49084
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: qede: confirm skb is allocated before using qede_build_skb() assumes build_skb() always works and goes straight to skb_reserve(). However, build_skb() can fail under memory pressure. This re…

linux linux_kernel
0.01EPSS
CVE-2022-48829
Critica 9.1

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes iattr::ia_size is a loff_t, so these NFSv3 procedures must be careful to deal with incoming client size values that are larger t…

linux linux_kernel
0.01EPSS
CVE-2022-48743
Alta 8.1

In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix …

linux linux_kernel
0.01EPSS
CVE-2024-38618
Media 5.5

In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Set lower bound of start tick time Currently ALSA timer doesn't have the lower limit of the start tick time, and it allows a very small size, e.g. 1 tick with 1ns resolution for…

linux linux_kernel
0.01EPSS
CVE-2024-35869
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: guarantee refcounted children from parent session Avoid potential use-after-free bugs when walking DFS referrals, mounting and performing DFS failover by ensuring that all child…

linux linux_kernel
0.01EPSS
CVE-2016-8658
Media 6.1

Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified othe…

linux linux_kernel
0.01EPSS
CVE-2003-0462
Bassa 1.2

A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).

linux linux_kernel · mandrakesoft mandrake_linux · mandrakesoft mandrake_linux_corporate_server · mandrakesoft mandrake_multi_network_firewall
0.01EPSS
CVE-2024-42110
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx() The following is emitted when using idxd (DSA) dmanegine as the data mover for ntb_transport that ntb_netde…

linux linux_kernel
0.01EPSS
CVE-2023-52834
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: atl1c: Work around the DMA RX overflow issue This is based on alx driver commit 881d0327db37 ("net: alx: Work around the DMA RX overflow issue"). The alx and atl1c drivers had RX overflow e…

linux linux_kernel
0.01EPSS
CVE-2024-26826
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data re-injection from stale subflow When the MPTCP PM detects that a subflow is stale, all the packet scheduler must re-inject all the mptcp-level unacked data. To avoid acquirin…

linux linux_kernel
0.01EPSS
CVE-2015-7799
Media 4.9

The slhc_init function in drivers/net/slip/slhc.c in the Linux kernel through 4.2.3 does not ensure that certain slot numbers are valid, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted PPPIOCSMAXC…

linux linux_kernel
0.01EPSS
CVE-2022-49094
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: net/tls: fix slab-out-of-bounds bug in decrypt_internal The memory size of tls_ctx->rx.iv for AES128-CCM is 12 setting in tls_set_sw_offload(). The return value of crypto_aead_ivsize() for "…

linux linux_kernel
0.01EPSS
CVE-2019-25044
Alta 7.8

The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue.

linux linux_kernel · netapp cloud_backup · netapp h300e_firmware · netapp h300s_firmware · e altri 8
0.01EPSS