imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2018-25015
Alta 7.8

An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8.

linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · netapp h410c_firmware · e altri 5
0.01EPSS
CVE-2020-27152
Media 5.5

An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9.

linux linux_kernel
0.01EPSS
CVE-2015-8785
Media 6.2

The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov.

linux linux_kernel · suse linux_enterprise_real_time_extension
0.01EPSS
CVE-2014-7825
Alta 7.8

kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protectio…

linux linux_kernel
0.01EPSS
CVE-2024-47749
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Added NULL check for lookup_atid The lookup_atid() function can return NULL if the ATID is invalid or does not exist in the identifier table, which could lead to dereferencing a …

linux linux_kernel
0.01EPSS
CVE-2019-17056
Bassa 3.3

llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-3a359798b176.

linux linux_kernel
0.01EPSS
CVE-2021-33033
Alta 7.8

The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value.

linux linux_kernel
0.01EPSS
CVE-2020-25211
Media 6.0

In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netli…

debian debian_linux · fedoraproject fedora · linux linux_kernel
0.01EPSS
CVE-2018-21008
Media 5.5

An issue was discovered in the Linux kernel before 4.16.7. A use-after-free can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c.

linux linux_kernel
0.01EPSS
CVE-2018-14734
Alta 7.8

drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free).

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2015-5307
Media 4.9

The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · oracle vm_virtualbox · e altri 1
0.01EPSS
CVE-2013-4591
Media 6.2

Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxattr system c…

linux linux_kernel
0.01EPSS
CVE-2011-4127
Media 4.6

The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.

linux linux_kernel · suse linux_enterprise_server
0.01EPSS
CVE-2025-39688
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: nfsd: allow SC_STATUS_FREEABLE when searching via nfs4_lookup_stateid() The pynfs DELEG8 test fails when run against nfsd. It acquires a delegation and then lets the lease time out. It then …

linux linux_kernel
0.01EPSS
CVE-2023-4206
Alta 7.8

A use-after-free vulnerability in the Linux kernel's net/sched: cls_route component can be exploited to achieve local privilege escalation. When route4_change() is called on an existing filter, the whole tcf_result struct is always copied into the new instanc…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2020-27170
Media 4.7

An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel …

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · linux linux_kernel
0.01EPSS
CVE-2014-8369
Alta 7.8

The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly ha…

debian debian_linux · linux linux_kernel · opensuse evergreen · suse linux_enterprise_real_time_extension · e altri 1
0.01EPSS
CVE-2013-0217
Media 5.2

Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (memory consumption) by triggering certain error conditions.

linux linux_kernel
0.01EPSS
CVE-2024-44970
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink When all the strides in a WQE have been consumed, the WQE is unlinked from the WQ linked list (mlx5_wq_ll_pop()). For SHAMPO, it is possi…

linux linux_kernel
0.01EPSS
CVE-2023-4147
Alta 7.8

A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.

debian debian_linux · fedoraproject fedora · linux linux_kernel · redhat enterprise_linux · e altri 4
0.01EPSS
CVE-2018-19824
Alta 7.8

In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2005-0124
Bassa 2.1

The coda_pioctl function in the coda functionality (pioctl.c) for Linux kernel 2.6.9 and 2.4.x before 2.4.29 may allow local users to cause a denial of service (crash) or execute arbitrary code via negative vi.in_size or vi.out_size values, which may trigger a…

linux linux_kernel
0.01EPSS
CVE-2026-43037
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as str…

linux linux_kernel
0.01EPSS
CVE-2024-53095
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS triggers oops while reconnecting to a server. [0] The workload runs on Kubernetes, and so…

linux linux_kernel
0.01EPSS
CVE-2024-50185
Alta 8.2

In the Linux kernel, the following vulnerability has been resolved: mptcp: handle consistently DSS corruption Bugged peer implementation can send corrupted DSS options, consistently hitting a few warning in the data path. Use DEBUG_NET assertions, to avoid t…

linux linux_kernel
0.01EPSS