imPC@ndo EN

Vulnerabilità Linux

14.775 CVE

CVE-2011-0463
Bassa 2.1

The ocfs2_prepare_page_for_write function in fs/ocfs2/aops.c in the Oracle Cluster File System 2 (OCFS2) subsystem in the Linux kernel before 2.6.39-rc1 does not properly handle holes that cross page boundaries, which allows local users to obtain potentially s…

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2007-6716
Media 5.5

fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · novell linux_desktop · e altri 3
0.01EPSS
CVE-2005-2708
Bassa 2.1

The search_binary_handler function in exec.c in Linux 2.4 kernel on 64-bit x86 architectures does not check a return code for a particular function call when virtual memory is low, which allows local users to cause a denial of service (panic), as demonstrated …

linux linux_kernel
0.01EPSS
CVE-2026-53391
Alta 7.5

In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr nfs4_decode_mp_ds_addr() decodes the r_netid and r_addr opaques of a netaddr4 from a GETDEVICEINFO multipath-DS body, then imm…

linux linux_kernel
0.01EPSS
CVE-2026-53224
Critica 9.1

In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list lengths in cookie sctp_unpack_cookie() only checked that the embedded INIT chunk length did not exceed the remaining cookie payload, but d…

linux linux_kernel
0.01EPSS
CVE-2020-11565
Media 6.0

An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa. NOTE: Someone in the security community…

canonical ubuntu_linux · linux linux_kernel
0.01EPSS
CVE-2010-1451
Bassa 2.1

The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which ma…

debian debian_linux · linux linux_kernel
0.01EPSS
CVE-2004-2136
Bassa 2.1

dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a block size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked files to be detected without decryption.

linux linux_kernel
0.01EPSS
CVE-2024-50162
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: bpf: devmap: provide rxq after redirect rxq contains a pointer to the device from where the redirect happened. Currently, the BPF program that was executed after a redirect via BPF_MAP_TYPE_…

linux linux_kernel
0.01EPSS
CVE-2023-39191
Alta 8.2

An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF p…

fedoraproject fedora · linux linux_kernel · redhat enterprise_linux
0.01EPSS
CVE-2011-1076
Media 4.9

net/dns_resolver/dns_key.c in the Linux kernel before 2.6.38 allows remote DNS servers to cause a denial of service (NULL pointer dereference and OOPS) by not providing a valid response to a DNS query, as demonstrated by an erroneous grand.centrall.org query, …

linux linux_kernel
0.01EPSS
CVE-2011-1771
Alta 7.8

The cifs_close function in fs/cifs/file.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact by setting the O_DIRECT flag during an attempt to open a fi…

linux linux_kernel
0.01EPSS
CVE-2009-2848
Media 5.9

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system cal…

canonical ubuntu_linux · fedoraproject fedora · linux linux_kernel · novell linux_desktop · e altri 8
0.01EPSS
CVE-2021-4002
Media 4.4

A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to ge…

debian debian_linux · fedoraproject fedora · linux linux_kernel · oracle communications_cloud_native_core_binding_support_function · e altri 2
0.01EPSS
CVE-2020-11725
Alta 7.8

snd_ctl_elem_add in sound/core/control.c in the Linux kernel through 5.6.3 has a count=info->owner line, which later affects a private_size*count multiplication for unspecified "interesting side effects." NOTE: kernel engineers dispute this finding, because it…

linux linux_kernel
0.01EPSS
CVE-2016-4951
Alta 7.8

The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact vi…

canonical ubuntu_linux · linux linux_kernel · oracle linux
0.01EPSS
CVE-2014-3690
Media 5.5

arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial…

canonical ubuntu_linux · debian debian_linux · linux linux_kernel · novell suse_linux_enterprise_desktop · e altri 6
0.01EPSS
CVE-2026-53399
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4_alloc_stid() publishes the new stid into cl->cl_stateids via idr_alloc_cyclic() under cl_lock before returning to nfsd4_alloc_layout_statei…

linux linux_kernel
0.01EPSS
CVE-2026-53398
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfse…

linux linux_kernel
0.01EPSS
CVE-2026-53228
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function entry and continues using it after iptunnel_handle_offloads(). Fo…

linux linux_kernel
0.01EPSS
CVE-2026-53225
Critica 9.1

In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then c…

linux linux_kernel
0.01EPSS
CVE-2026-53221
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(), when an exact match for a tunnel fails, the code falls back to searching for wildcard tunnels: - Tunnels ma…

linux linux_kernel
0.01EPSS
CVE-2026-53186
Critica 9.1

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() copies sense data from rsp->data + resp_data_len, where resp_data_len is the full 32-bit value supplied by the SRP…

linux linux_kernel
0.01EPSS
CVE-2026-53045
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: memory: tegra124-emc: Fix dll_change check The code checking whether the specified memory timing enables DLL in the EMRS register was reversed. DLL is enabled if bit A0 is low. Fix the check…

linux linux_kernel
0.01EPSS
CVE-2026-53043
Critica 9.1

In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()". In dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGI…

linux linux_kernel
0.01EPSS