imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2024-50251
Media 6.2

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() If access to offset + length is larger than the skbuff length, then skb_checksum() triggers BUG_ON(). skb_ch…

linux linux_kernel
0.01EPSS
CVE-2013-2164
Bassa 2.1

The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.

linux linux_kernel · redhat enterprise_linux · redhat enterprise_mrg
0.01EPSS
CVE-2010-4160
Media 6.9

Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a den…

linux linux_kernel · opensuse opensuse · suse linux_enterprise_desktop · suse linux_enterprise_server · e altri 1
0.01EPSS
CVE-2008-1514
Media 4.9

arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an i…

linux linux_kernel
0.01EPSS
CVE-2024-26692
Alta 8.3

In the Linux kernel, the following vulnerability has been resolved: smb: Fix regression in writes when non-standard maximum write size negotiated The conversion to netfs in the 6.3 kernel caused a regression when maximum write size is set by the server to an…

linux linux_kernel
0.01EPSS
CVE-2020-26541
Media 6.5

The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

linux linux_kernel
0.01EPSS
CVE-2018-14656
Alta 7.0

A missing address check in the callers of the show_opcodes() in the Linux kernel allows an attacker to dump the kernel memory at an arbitrary kernel address into the dmesg log.

linux linux_kernel
0.01EPSS
CVE-2024-53122
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust Additional active subflows - i.e. created by the in kernel path manager - are included into the subflow list before starting the…

linux linux_kernel
0.01EPSS
CVE-2024-46695
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on files on an NFS filesy…

linux linux_kernel
0.01EPSS
CVE-2008-1675
Alta 7.2

The bdx_ioctl_priv function in the tehuti driver (tehuti.c) in Linux kernel 2.6.x before 2.6.25.1 does not properly check certain information related to register size, which has unspecified impact and local attack vectors, probably related to reading or writin…

linux linux_kernel
0.01EPSS
CVE-2005-0529
Bassa 2.1

Linux kernel 2.6.10 and 2.6.11rc1-bk6 uses different size types for offset arguments to the proc_file_read and locks_read_proc functions, which leads to a heap-based buffer overflow when a signed comparison causes negative integers to be used in a positive con…

linux linux_kernel
0.01EPSS
CVE-2024-38623
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Use variable length array instead of fixed size Should fix smatch warning: ntfs_set_label() error: __builtin_memcpy() 'uni->name' too small (20 vs 256)

linux linux_kernel
0.01EPSS
CVE-2023-6606
Alta 7.1

An out-of-bounds read vulnerability was found in smbCalcSize in fs/smb/client/netmisc.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information.

linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_eus · redhat enterprise_linux_server_aus · e altri 1
0.01EPSS
CVE-2022-1734
Alta 7.0

A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.

debian debian_linux · linux linux_kernel · netapp h300e_firmware · netapp h300s_firmware · e altri 6
0.01EPSS
CVE-2008-2365
Media 4.7

Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's pro…

linux linux_kernel · redhat enterprise_linux · redhat enterprise_linux_desktop
0.01EPSS
CVE-2026-46331
Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page cache corruption tcf_pedit_act() computes the COW range for skb_ensure_writable() once before the key loop using tcfp_off_max_hint, but the h…

linux linux_kernel
0.01EPSS
CVE-2026-46119
Critica 9.1

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treate…

linux linux_kernel
0.01EPSS
CVE-2008-3528
Bassa 2.1

The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate atta…

linux linux_kernel
0.01EPSS
CVE-2006-6056
Media 4.9

Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demo…

linux linux_kernel
0.01EPSS
CVE-2026-53046
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine ksmbd_crypt_message() sets a NULL completion callback on AEAD requests and does not handle the -EINPROGRESS return code …

linux linux_kernel
0.01EPSS
CVE-2024-49568
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg When receiving proposal msg in server, the fields v2_ext_offset/ eid_cnt/ism_gid_cnt in proposal msg are from the…

linux linux_kernel
0.01EPSS
CVE-2024-50256
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6() I got a syzbot report without a repro [1] crashing in nf_send_reset6() I think the issue is that dev->hard_header_len is z…

linux linux_kernel
0.01EPSS
CVE-2019-15924
Media 5.5

An issue was discovered in the Linux kernel before 5.0.11. fm10k_init_module in drivers/net/ethernet/intel/fm10k/fm10k_main.c has a NULL pointer dereference because there is no -ENOMEM upon an alloc_workqueue failure.

linux linux_kernel
0.01EPSS
CVE-2014-1738
Bassa 2.1

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel he…

debian debian_linux · linux linux_kernel · oracle linux · redhat enterprise_linux_eus · e altri 4
0.01EPSS
CVE-2013-4163
Media 4.7

The ip6_append_data_mtu function in net/ipv6/ip6_output.c in the IPv6 implementation in the Linux kernel through 3.10.3 does not properly maintain information about whether the IPV6_MTU setsockopt option had been specified, which allows local users to cause a …

linux linux_kernel
0.01EPSS